summaryrefslogtreecommitdiff
path: root/users
diff options
context:
space:
mode:
authorRobin H. Johnson <robbat2@gentoo.org>2008-10-09 21:33:11 +0000
committerRobin H. Johnson <robbat2@gentoo.org>2008-10-09 21:33:11 +0000
commitf3b8ecb968fff44716f90a4aa424e27dea8f8342 (patch)
tree4da8a8b3106d26d7ceddd739f9b62e73a54229f2 /users
parentI think this was done already. (diff)
downloadgentoo-f3b8ecb968fff44716f90a4aa424e27dea8f8342.tar.gz
gentoo-f3b8ecb968fff44716f90a4aa424e27dea8f8342.tar.bz2
gentoo-f3b8ecb968fff44716f90a4aa424e27dea8f8342.zip
Fix sentence structure.
Diffstat (limited to 'users')
-rw-r--r--users/robbat2/tree-signing-gleps/01-distribution-process-security12
1 files changed, 6 insertions, 6 deletions
diff --git a/users/robbat2/tree-signing-gleps/01-distribution-process-security b/users/robbat2/tree-signing-gleps/01-distribution-process-security
index dfca34997c..db49590712 100644
--- a/users/robbat2/tree-signing-gleps/01-distribution-process-security
+++ b/users/robbat2/tree-signing-gleps/01-distribution-process-security
@@ -1,7 +1,7 @@
GLEP: xx+1
Title: Security of distribution of Gentoo software - Infrastructure to User distribution - MetaManifest
-Version: $Revision: 1.21 $
-Last-Modified: $Date: 2008/10/09 21:11:21 $
+Version: $Revision: 1.22 $
+Last-Modified: $Date: 2008/10/09 21:33:11 $
Author: Robin Hugh Johnson <robbat2@gentoo.org>,
Status: Draft
Type: Standards Track
@@ -52,8 +52,8 @@ No other guarantees, either implicit or explicit are made.
Additionally, distributing a set of the most recent MetaManifests from a
trusted source allows validation of trees that come from community
-mirrors, and allows detection of malicious (either by deliberate delay,
-replay [C08a, C08b] or alteration community mirrors.
+mirrors, and allows detection of all cases of malicious mirrors (either
+by deliberate delay, replay [C08a, C08b] or alteration).
=============
Specification
@@ -224,11 +224,11 @@ trusted channel.
On all rsync mirrors directly maintained by the Gentoo infrastructure,
and not on community mirrors, there should be a new module
'gentoo-portage-metamanifests'. Within this module, all MetaManifests
-for a recent timeframe (eg one week) should be kept, named as
+for a recent time frame (eg one week) should be kept, named as
"MetaManifest.$TS", where $TS is the timestamp from inside the file.
The most recent MetaManifest should always be symlinked as
MetaManifest.current. The possibility of serving the recent
-MetaManifests via HTTPS should also be explored to mitigate MITM
+MetaManifests via HTTPS should also be explored to mitigate MitM
attacks.
The package manager should obtain MetaManifest.current and use it to