[Reproducible-builds] Reproducibility vs signatures

Ben Hutchings ben at decadent.org.uk
Mon Aug 3 10:40:16 UTC 2015


On Mon, 2015-08-03 at 12:27 +0200, Holger Levsen wrote:
> Hi,
> 
> On Montag, 3. August 2015, Ben Hutchings wrote:
> > That sort of works as long as there's only one architecture we want to
> > do this for.  But the ability to verify modules is useful in general so
> > I would like to turn that on for all architectures.
> 
> how is this going to work for builds on buildds anyway? I suppose you are not 
> planning to build+sign all arch manually?
> 
> And who can sign those kernels anyway? I suppose anybody should stil be able 
> to build+sign+boot kernels, or?

See <https://lists.debian.org/debian-kernel/2013/08/msg00267.html>.

Ben.

-- 
Ben Hutchings
Unix is many things to many people,
but it's never been everything to anybody.

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 811 bytes
Desc: This is a digitally signed message part
URL: <http://lists.alioth.debian.org/pipermail/reproducible-builds/attachments/20150803/e1954098/attachment.sig>


More information about the Reproducible-builds mailing list