[gobolinux-users] Gnupg & CreatePackage

Lucas C. Villa Real lucasvr at gobolinux.org
Thu Aug 10 21:10:46 GMT 2006


On 8/10/06, teique <teique at gmail.com> wrote:
> ok but each time I CreatePackage I have to enter a password *ugh*

Yes, that's the password for your gpg key, which will be used to sign
the package with your identity.

> btw the generated .tar.bz2/signature has something to do with my "gpg key"?
> I mean, if someone else CreatePackate based on the exactly same
> installed Program the .tar.bz2 will have any difference??

Yes, they'll differ on Resources/FileHash.sig and Resources/FileHash.
InstallPackage  will check for the hashes to certify that all files
stored in the package have been created by you (avoiding problems with
malicious files injected in the package).

-- 
Lucas
powered by /dev/dsp


More information about the gobolinux-users mailing list