--- xml/htdocs/proj/en/glep/glep-0059.html 2010/01/31 08:50:52 1.7 +++ xml/htdocs/proj/en/glep/glep-0059.html 2010/01/31 09:56:08 1.8 @@ -27,9 +27,9 @@ Title:Manifest2 hash policies and security implications -Version:1.5 +Version:1.6 -Last-Modified:2010/01/31 07:55:45 +Last-Modified:2010/01/31 09:55:43 Author:Robin Hugh Johnson <robbat2 at gentoo.org>, @@ -85,6 +85,9 @@ tree, but is only tangentially related to the actual signing of Manifests. Checksums present one possible weak point in the overall security of the tree - and a comprehensive security plan is needed.

+

This GLEP is not mandatory for the tree-signing specification, but +instead aims to improve the security of the hashes used in Manifest2. +As such, it is also able to stand on it's own.

Specification

@@ -244,7 +247,7 @@