From: Eric Hodel Date: 2004-06-25T02:44:30+09:00 Subject: Re: rubygems thoughts --DzFMwNuU1QL7hgxO Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Hans Fugal (hfugal@wencor.com) wrote: >=20 > > > >There's unfortunately no security mechanism in RubyGems atm.; this is > >somewhat difficult due to RubyGems "distributed" nature, where the > >packaging work is pushed down to upstream developers, so even if gem > >signatures were implemented, building the web of trust could take some > >time. > > >=20 > A good start would be working in signatures and letting people do with=20 > that whatever seems natural. For example, if I were to release a gem I'd= =20 > like to sign it and provide my public key on the official project=20 > website, or the fingerprint of it which can be got from a public=20 > keyserver. That requires a manual check by the user to be of any use,=20 > but once the infrastructure is there other things can evolve, like some= =20 > repositories would have an upload system where developers must sign the= =20 > gem and they are allowed to upload with their signature for a set of=20 > packages. Ruby comes with OpenSSL built-in now, so this need not be a manual check. --=20 Eric Hodel - drbrain@segment7.net - http://segment7.net All messages signed with fingerprint: FEC2 57F1 D465 EB15 5D6E 7C11 332A 551C 796C 9F04 --DzFMwNuU1QL7hgxO Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.2 (FreeBSD) iD8DBQFA2xL8MypVHHlsnwQRAhRxAJ9TmCb0VSuMItgwGLOyE6eyXXmwiwCfVb/X K5VqALy6LeAiET/z2MpAROQ= =Y6lj -----END PGP SIGNATURE----- --DzFMwNuU1QL7hgxO--