[gobolinux-users] Gnupg & CreatePackage
Lucas C. Villa Real
lucasvr at gobolinux.org
Thu Aug 10 21:10:46 GMT 2006
On 8/10/06, teique <teique at gmail.com> wrote:
> ok but each time I CreatePackage I have to enter a password *ugh*
Yes, that's the password for your gpg key, which will be used to sign
the package with your identity.
> btw the generated .tar.bz2/signature has something to do with my "gpg key"?
> I mean, if someone else CreatePackate based on the exactly same
> installed Program the .tar.bz2 will have any difference??
Yes, they'll differ on Resources/FileHash.sig and Resources/FileHash.
InstallPackage will check for the hashes to certify that all files
stored in the package have been created by you (avoiding problems with
malicious files injected in the package).
--
Lucas
powered by /dev/dsp
More information about the gobolinux-users
mailing list