diff options
author | Robin H. Johnson <robbat2@gentoo.org> | 2008-10-09 21:33:11 +0000 |
---|---|---|
committer | Robin H. Johnson <robbat2@gentoo.org> | 2008-10-09 21:33:11 +0000 |
commit | f3b8ecb968fff44716f90a4aa424e27dea8f8342 (patch) | |
tree | 4da8a8b3106d26d7ceddd739f9b62e73a54229f2 /users | |
parent | I think this was done already. (diff) | |
download | gentoo-f3b8ecb968fff44716f90a4aa424e27dea8f8342.tar.gz gentoo-f3b8ecb968fff44716f90a4aa424e27dea8f8342.tar.bz2 gentoo-f3b8ecb968fff44716f90a4aa424e27dea8f8342.zip |
Fix sentence structure.
Diffstat (limited to 'users')
-rw-r--r-- | users/robbat2/tree-signing-gleps/01-distribution-process-security | 12 |
1 files changed, 6 insertions, 6 deletions
diff --git a/users/robbat2/tree-signing-gleps/01-distribution-process-security b/users/robbat2/tree-signing-gleps/01-distribution-process-security index dfca34997c..db49590712 100644 --- a/users/robbat2/tree-signing-gleps/01-distribution-process-security +++ b/users/robbat2/tree-signing-gleps/01-distribution-process-security @@ -1,7 +1,7 @@ GLEP: xx+1 Title: Security of distribution of Gentoo software - Infrastructure to User distribution - MetaManifest -Version: $Revision: 1.21 $ -Last-Modified: $Date: 2008/10/09 21:11:21 $ +Version: $Revision: 1.22 $ +Last-Modified: $Date: 2008/10/09 21:33:11 $ Author: Robin Hugh Johnson <robbat2@gentoo.org>, Status: Draft Type: Standards Track @@ -52,8 +52,8 @@ No other guarantees, either implicit or explicit are made. Additionally, distributing a set of the most recent MetaManifests from a trusted source allows validation of trees that come from community -mirrors, and allows detection of malicious (either by deliberate delay, -replay [C08a, C08b] or alteration community mirrors. +mirrors, and allows detection of all cases of malicious mirrors (either +by deliberate delay, replay [C08a, C08b] or alteration). ============= Specification @@ -224,11 +224,11 @@ trusted channel. On all rsync mirrors directly maintained by the Gentoo infrastructure, and not on community mirrors, there should be a new module 'gentoo-portage-metamanifests'. Within this module, all MetaManifests -for a recent timeframe (eg one week) should be kept, named as +for a recent time frame (eg one week) should be kept, named as "MetaManifest.$TS", where $TS is the timestamp from inside the file. The most recent MetaManifest should always be symlinked as MetaManifest.current. The possibility of serving the recent -MetaManifests via HTTPS should also be explored to mitigate MITM +MetaManifests via HTTPS should also be explored to mitigate MitM attacks. The package manager should obtain MetaManifest.current and use it to |