Re: [gnu-prog-discuss] Introducing GNU Guix

From: Niels Möller
Subject: Re: [gnu-prog-discuss] Introducing GNU Guix
Date: Fri, 23 Nov 2012 21:21:02 +0100
address@hidden (Ludovic Courtès) writes:

> The TODO item about signatures is to verify the OpenPGP signature that
> comes with GNU packages.

I see, then you don't have much choice on signature format. And I agree
it's a useful feature.

You might like expressing authorizations as sexps (and I guess its
possible to use the spki machinery even with alien input formats like

I was thinking of using spki delegations for things like "this key can
authorize installation of packages from these urls" or "this key is
authorized to install files in this subtree in the file system". But I
haven't thought carefully about how that should work.

Happy hacking,

Niels Möller. PGP-encrypted email is preferred. Keyid C0B98E26.
Internet email is subject to wholesale government surveillance.

