View Single Post
Posts: 540 | Thanked: 288 times | Joined on Sep 2009
#42
Originally Posted by zimon View Post
That is one of the many reasons why DEB packages should be required to have embedded GPG signature of a packager
Everyone interested in this discussion should see the SELinux thread and continue there.

For those not interested in reading that thread "just because" I point this question (replies to the SELinux thread please): How do you verify that the signature is actually of a real person that is actually the packager (and how to make this easy for the end-user?)
 

The Following User Says Thank You to rambo For This Useful Post: