| … | |
… | |
| 25 | <tbody valign="top"> |
25 | <tbody valign="top"> |
| 26 | <tr class="field"><th class="field-name">GLEP:</th><td class="field-body">59</td> |
26 | <tr class="field"><th class="field-name">GLEP:</th><td class="field-body">59</td> |
| 27 | </tr> |
27 | </tr> |
| 28 | <tr class="field"><th class="field-name">Title:</th><td class="field-body">Manifest2 hash policies and security implications</td> |
28 | <tr class="field"><th class="field-name">Title:</th><td class="field-body">Manifest2 hash policies and security implications</td> |
| 29 | </tr> |
29 | </tr> |
| 30 | <tr class="field"><th class="field-name">Version:</th><td class="field-body">1.4</td> |
30 | <tr class="field"><th class="field-name">Version:</th><td class="field-body">1.6</td> |
| 31 | </tr> |
31 | </tr> |
| 32 | <tr class="field"><th class="field-name">Last-Modified:</th><td class="field-body"><a class="reference external" href="http://www.gentoo.org/cgi-bin/viewcvs.cgi/xml/htdocs/proj/en/glep/glep-0059.txt?cvsroot=gentoo">2010/01/13 03:26:53</a></td> |
32 | <tr class="field"><th class="field-name">Last-Modified:</th><td class="field-body"><a class="reference external" href="http://www.gentoo.org/cgi-bin/viewcvs.cgi/xml/htdocs/proj/en/glep/glep-0059.txt?cvsroot=gentoo">2010/01/31 09:55:43</a></td> |
| 33 | </tr> |
33 | </tr> |
| 34 | <tr class="field"><th class="field-name">Author:</th><td class="field-body">Robin Hugh Johnson <robbat2 at gentoo.org>,</td> |
34 | <tr class="field"><th class="field-name">Author:</th><td class="field-body">Robin Hugh Johnson <robbat2 at gentoo.org>,</td> |
| 35 | </tr> |
35 | </tr> |
| 36 | <tr class="field"><th class="field-name">Status:</th><td class="field-body">Draft</td> |
36 | <tr class="field"><th class="field-name">Status:</th><td class="field-body">Draft</td> |
| 37 | </tr> |
37 | </tr> |
| … | |
… | |
| 83 | <h1><a class="toc-backref" href="#id2">Motivation</a></h1> |
83 | <h1><a class="toc-backref" href="#id2">Motivation</a></h1> |
| 84 | <p>This GLEP is being written as part of the work on signing the Portage |
84 | <p>This GLEP is being written as part of the work on signing the Portage |
| 85 | tree, but is only tangentially related to the actual signing of |
85 | tree, but is only tangentially related to the actual signing of |
| 86 | Manifests. Checksums present one possible weak point in the overall |
86 | Manifests. Checksums present one possible weak point in the overall |
| 87 | security of the tree - and a comprehensive security plan is needed.</p> |
87 | security of the tree - and a comprehensive security plan is needed.</p> |
|
|
88 | <p>This GLEP is not mandatory for the tree-signing specification, but |
|
|
89 | instead aims to improve the security of the hashes used in Manifest2. |
|
|
90 | As such, it is also able to stand on it's own.</p> |
| 88 | </div> |
91 | </div> |
| 89 | <div class="section" id="specification"> |
92 | <div class="section" id="specification"> |
| 90 | <h1><a class="toc-backref" href="#id3">Specification</a></h1> |
93 | <h1><a class="toc-backref" href="#id3">Specification</a></h1> |
| 91 | <div class="section" id="the-bad-news"> |
94 | <div class="section" id="the-bad-news"> |
| 92 | <h2><a class="toc-backref" href="#id4">The bad news</a></h2> |
95 | <h2><a class="toc-backref" href="#id4">The bad news</a></h2> |
| … | |
… | |
| 242 | |
245 | |
| 243 | </div> |
246 | </div> |
| 244 | <div class="footer"> |
247 | <div class="footer"> |
| 245 | <hr class="footer" /> |
248 | <hr class="footer" /> |
| 246 | <a class="reference external" href="glep-0059.txt">View document source</a>. |
249 | <a class="reference external" href="glep-0059.txt">View document source</a>. |
| 247 | Generated on: 2010-01-31 07:53 UTC. |
250 | Generated on: 2010-01-31 09:56 UTC. |
| 248 | Generated by <a class="reference external" href="http://docutils.sourceforge.net/">Docutils</a> from <a class="reference external" href="http://docutils.sourceforge.net/rst.html">reStructuredText</a> source. |
251 | Generated by <a class="reference external" href="http://docutils.sourceforge.net/">Docutils</a> from <a class="reference external" href="http://docutils.sourceforge.net/rst.html">reStructuredText</a> source. |
| 249 | |
252 | |
| 250 | </div> |
253 | </div> |
| 251 | </body> |
254 | </body> |
| 252 | </html> |
255 | </html> |