
Hi all, I've finally gotten around to looking at signing repos and have put a signed copy of [haskell-core] on kiwilight. I'd appreciate someone else testing it before I take the step to sign [haskell-core] itself. Here's the config I use at the moment: [haskell-test] SigLevel = Required TrustedOnly Server = http://www.kiwilight.com/haskell/test Oh, and this is x86_64 only at the moment! This is the key I've used for signing: -----BEGIN PGP PUBLIC KEY BLOCK----- Version: GnuPG v2.0.19 (GNU/Linux) mQMuBFDbKz8RCACkf/BFm1KCsQQ3+5IvzKMSuQ4MMmhQc83hhxdG/Xo+GJdsgQoE 7IuRgPhKN3I+4FYaZY+WXImpDIbggWx/29cu6jeMs6zOcE3Oyz70ycJY3Rd639Ua RriGGYLEgiZ4vSgzj6TbONcH1PURonddjquvupNOTlqWrnfRgM3b/yxyVFi4wGtH w22E1feDvCYvERWER0KrKSGmUrp/NXwmNTPtNPIzLsgs8ivR7ThqrdwcygKLKk6j QeZbe6MI7mG+gEMhfipK+71Q3nJK1hl8lAW2Ai296nDjoxw55OqdgTOtv0RbMg70 R5EkQgqtTv6R6D31eQmZ41Rsb1eosXS+LmYHAQDZ0A6iE/jsr4ncMvrCIKaL2sb4 LMt9Ri+i5/SkSBL7cwf+J4w9dHK5eGhMPntypbyhnzV6cSgDtT7UwjzzJzIkExoO fF6ovOq45m5/tYQW4EbqrHyb2VP91j1AOh4EYIlnoW3FylH951OOfG4kXYdTZjVB bQ6z1Ck7/AcLCv7TosdqJ5bABTPSJyXKaDJlXnrZAdXyvNFZpCxlr6DIDUr9dpYU U1/h6x2Do4S8EV5dpWJO2NIkNpT60FOz8w+5Ce9GankhKschH5yzA0jwIgM9g6Sm WpjDpK3tZ7TpLFwuMld2GDchCfgKv9Fsj+VNxU11R17H1taOlyKdYH6GJW3AR0CF ask4jWZC9oONwi6mDaSRcpPQtCodnikLKTefXm3g9wf/Q+lj1gdrHpg0MbjO+V3V e6DJXjypdCZtNRG7c49bc1mmA78JBrProDKI+Una/dFDd97zkwMbi12m8Eg+i4EL B7qQnTLtHXTM/GtpDe0Q6Gvf2/l6s5Oh4WuIzqsf2dHpQM2u2YlXKBk97ffDM4eY gR1rinXmgx7I82GuBImFEuXatMs/0y3D/vwGdFfGs27PMRMVnqGowpOK7e0dUAVn xul8FCEuq6Jch7SXtvVVMUScVRDS0RbIQVuw57om1uefETPNvh19RCJKL2sWNJcX LRbWLGQgHoH8vtmmapUlvQCdVHPCnE31k+4gkBL/CmjS4kztXxJEX4LwWVieMdGM n7QzQXJjaEhhc2tlbGwgKE1hZ251cyBUaGVybmluZykgPG1hZ251c0B0aGVybmlu Zy5vcmc+iHoEExEIACIFAlDbKz8CGwMGCwkIBwMCBhUIAgkKCwQWAgMBAh4BAheA AAoJEDKwtFNCCRcLfgwBAMXxHO5UtX/ubTJPwpMAzFZw7T4R0FyfRHDriOFbYdz1 APsHAC4M7LdyA+RgbUKjpLKVTXvx3LvFOOkXx4KFWfYzYbkDLgRQ2zBgEQgAxnCJ j6q/59KDQ/jvFD9h7TmzXw8qRfu0J+xq1CIotMld+HPI7vehLqA1Dd4JC3AMxxfH safF/aOJ8OaYWDLnsDFG09aOhj8nEC4mcNZv63atn3/HMjl89Q8N4H5x+SdZLlBG 1BmAh3WcOvAkgBn2vmT9aY+lYuMwFGliqq8GS+NYaHWJ9GXuLvByQSfxOIxMXYGv NB36o1LE7+Z7l3JJVu/3Vy4PG/jWgrRgUpFFYXimA9RI66c66S7+3MywctIhzIAS yC2HQ5Ljm6rfhZk7zWXuHXNO3vKODF0aWGsxCf/h8lpQxT9BoM373ksUp10OAFLv CtQOVqzkZkt3vLStkwEA44v9427wGSCEdb8IA2BDFnVio1mcRJgYb+Tp1+cKjvMH /jf4haJXGD8g8YDMW293CasBNluKRBFpsyV7Hkfw9XBaE900bcjettdZtIsOcgMH nTx/o9rYZGCPRJuISivs691x28hF31UIjtl5b25KOsQmnaRYeGaoooQUPKvm7yrR MXlwdej7v6fd2z1F71WpNGStAvJDf/fX8CWpHjHgvHtoPAwibE6CvC8b0vyb4Xex 5b8NrCC3Ma9LwEuiS3bcDU4VsHLPMa9qstBV6JiWhAhq6+yW1SZflmYhJb7zpOQC 4YPz1xKnmwi3ShSzWpBzebOjM6VsqYFZ3PGM0ovo002ZBqeX7zDxiOKnb8Fic/AP SjPQDaU5CUlNG40zXMdURO0IAIBO1XA4caZwjqMI/2j3S6tTB/kAsX5rR6VDwfKk vGYoekBRWZ+S0hpKwcI6k4c5JW/QGMYj6y/t9WVGvkAZ5+ks6fLXRcFHtzcyb1Kd rUBGBsWJu6h5i8/+bk2SepvBlQO+68GRbkdqqfcnkkBxAH/OT7VTLFTuJq2Bsn/5 oH/WOeNorR3JkdQnEnk3IZNjyk99ZKuusYoKQ8UjUQCNFzfL2ColnmKW/ikUr4HQ OBY/JUh9Ofn/y87TsoJ67rr2k/GAj5dmRqMfPiho/DAdoxUfuJj+43N6m2QrNvZC QjHXV0ZLZCPvDF9scHGqw0Xs3nnSbvLIGytQptB3Wj6zSmqIwQQYEQgACQUCUNsw YAIbAgBqCRAysLRTQgkXC18gBBkRCAAGBQJQ2zBgAAoJEJBRN1CkGMD+oiQA/0S2 McU6xwAsAqhftC5MZEvW57pXxPF+6CdgeptbbUTYAQCvWM1raAAxC+k+gg5UO1eS It9KScuDVbGnc/SyWmkXNz+eAP48RLu9FPD9FAhXLi4kTNzPMS4cJ/CnDkytxEJW vTpqvQD/YG+dOcF8SCkOHCzrEsrISLr//K55pkDbg4bGlYirHVk= =DzpX -----END PGP PUBLIC KEY BLOCK----- /M -- Magnus Therning OpenPGP: 0xAB4DFBA4 email: magnus@therning.org jabber: magnus@therning.org twitter: magthe http://therning.org/magnus

Hi Magnus, Everything seems to be working as expected. Have you overcome the problems of ensuring a secure custody chain? Also, could you send me a copy of the ArchHaskell key signed with your other key (0xAB4DFBA4)? Thanks for this! Regards, Xyne Magnus Therning wrote:
Hi all,
I've finally gotten around to looking at signing repos and have put a signed copy of [haskell-core] on kiwilight. I'd appreciate someone else testing it before I take the step to sign [haskell-core] itself. Here's the config I use at the moment:
[haskell-test] SigLevel = Required TrustedOnly Server = http://www.kiwilight.com/haskell/test
Oh, and this is x86_64 only at the moment!
This is the key I've used for signing:
-----BEGIN PGP PUBLIC KEY BLOCK----- Version: GnuPG v2.0.19 (GNU/Linux)
mQMuBFDbKz8RCACkf/BFm1KCsQQ3+5IvzKMSuQ4MMmhQc83hhxdG/Xo+GJdsgQoE 7IuRgPhKN3I+4FYaZY+WXImpDIbggWx/29cu6jeMs6zOcE3Oyz70ycJY3Rd639Ua RriGGYLEgiZ4vSgzj6TbONcH1PURonddjquvupNOTlqWrnfRgM3b/yxyVFi4wGtH w22E1feDvCYvERWER0KrKSGmUrp/NXwmNTPtNPIzLsgs8ivR7ThqrdwcygKLKk6j QeZbe6MI7mG+gEMhfipK+71Q3nJK1hl8lAW2Ai296nDjoxw55OqdgTOtv0RbMg70 R5EkQgqtTv6R6D31eQmZ41Rsb1eosXS+LmYHAQDZ0A6iE/jsr4ncMvrCIKaL2sb4 LMt9Ri+i5/SkSBL7cwf+J4w9dHK5eGhMPntypbyhnzV6cSgDtT7UwjzzJzIkExoO fF6ovOq45m5/tYQW4EbqrHyb2VP91j1AOh4EYIlnoW3FylH951OOfG4kXYdTZjVB bQ6z1Ck7/AcLCv7TosdqJ5bABTPSJyXKaDJlXnrZAdXyvNFZpCxlr6DIDUr9dpYU U1/h6x2Do4S8EV5dpWJO2NIkNpT60FOz8w+5Ce9GankhKschH5yzA0jwIgM9g6Sm WpjDpK3tZ7TpLFwuMld2GDchCfgKv9Fsj+VNxU11R17H1taOlyKdYH6GJW3AR0CF ask4jWZC9oONwi6mDaSRcpPQtCodnikLKTefXm3g9wf/Q+lj1gdrHpg0MbjO+V3V e6DJXjypdCZtNRG7c49bc1mmA78JBrProDKI+Una/dFDd97zkwMbi12m8Eg+i4EL B7qQnTLtHXTM/GtpDe0Q6Gvf2/l6s5Oh4WuIzqsf2dHpQM2u2YlXKBk97ffDM4eY gR1rinXmgx7I82GuBImFEuXatMs/0y3D/vwGdFfGs27PMRMVnqGowpOK7e0dUAVn xul8FCEuq6Jch7SXtvVVMUScVRDS0RbIQVuw57om1uefETPNvh19RCJKL2sWNJcX LRbWLGQgHoH8vtmmapUlvQCdVHPCnE31k+4gkBL/CmjS4kztXxJEX4LwWVieMdGM n7QzQXJjaEhhc2tlbGwgKE1hZ251cyBUaGVybmluZykgPG1hZ251c0B0aGVybmlu Zy5vcmc+iHoEExEIACIFAlDbKz8CGwMGCwkIBwMCBhUIAgkKCwQWAgMBAh4BAheA AAoJEDKwtFNCCRcLfgwBAMXxHO5UtX/ubTJPwpMAzFZw7T4R0FyfRHDriOFbYdz1 APsHAC4M7LdyA+RgbUKjpLKVTXvx3LvFOOkXx4KFWfYzYbkDLgRQ2zBgEQgAxnCJ j6q/59KDQ/jvFD9h7TmzXw8qRfu0J+xq1CIotMld+HPI7vehLqA1Dd4JC3AMxxfH safF/aOJ8OaYWDLnsDFG09aOhj8nEC4mcNZv63atn3/HMjl89Q8N4H5x+SdZLlBG 1BmAh3WcOvAkgBn2vmT9aY+lYuMwFGliqq8GS+NYaHWJ9GXuLvByQSfxOIxMXYGv NB36o1LE7+Z7l3JJVu/3Vy4PG/jWgrRgUpFFYXimA9RI66c66S7+3MywctIhzIAS yC2HQ5Ljm6rfhZk7zWXuHXNO3vKODF0aWGsxCf/h8lpQxT9BoM373ksUp10OAFLv CtQOVqzkZkt3vLStkwEA44v9427wGSCEdb8IA2BDFnVio1mcRJgYb+Tp1+cKjvMH /jf4haJXGD8g8YDMW293CasBNluKRBFpsyV7Hkfw9XBaE900bcjettdZtIsOcgMH nTx/o9rYZGCPRJuISivs691x28hF31UIjtl5b25KOsQmnaRYeGaoooQUPKvm7yrR MXlwdej7v6fd2z1F71WpNGStAvJDf/fX8CWpHjHgvHtoPAwibE6CvC8b0vyb4Xex 5b8NrCC3Ma9LwEuiS3bcDU4VsHLPMa9qstBV6JiWhAhq6+yW1SZflmYhJb7zpOQC 4YPz1xKnmwi3ShSzWpBzebOjM6VsqYFZ3PGM0ovo002ZBqeX7zDxiOKnb8Fic/AP SjPQDaU5CUlNG40zXMdURO0IAIBO1XA4caZwjqMI/2j3S6tTB/kAsX5rR6VDwfKk vGYoekBRWZ+S0hpKwcI6k4c5JW/QGMYj6y/t9WVGvkAZ5+ks6fLXRcFHtzcyb1Kd rUBGBsWJu6h5i8/+bk2SepvBlQO+68GRbkdqqfcnkkBxAH/OT7VTLFTuJq2Bsn/5 oH/WOeNorR3JkdQnEnk3IZNjyk99ZKuusYoKQ8UjUQCNFzfL2ColnmKW/ikUr4HQ OBY/JUh9Ofn/y87TsoJ67rr2k/GAj5dmRqMfPiho/DAdoxUfuJj+43N6m2QrNvZC QjHXV0ZLZCPvDF9scHGqw0Xs3nnSbvLIGytQptB3Wj6zSmqIwQQYEQgACQUCUNsw YAIbAgBqCRAysLRTQgkXC18gBBkRCAAGBQJQ2zBgAAoJEJBRN1CkGMD+oiQA/0S2 McU6xwAsAqhftC5MZEvW57pXxPF+6CdgeptbbUTYAQCvWM1raAAxC+k+gg5UO1eS It9KScuDVbGnc/SyWmkXNz+eAP48RLu9FPD9FAhXLi4kTNzPMS4cJ/CnDkytxEJW vTpqvQD/YG+dOcF8SCkOHCzrEsrISLr//K55pkDbg4bGlYirHVk= =DzpX -----END PGP PUBLIC KEY BLOCK-----
/M
-- Magnus Therning OpenPGP: 0xAB4DFBA4 email: magnus@therning.org jabber: magnus@therning.org twitter: magthe http://therning.org/magnus
_______________________________________________ arch-haskell mailing list arch-haskell@haskell.org http://www.haskell.org/mailman/listinfo/arch-haskell

On Fri, Dec 28, 2012 at 1:25 AM, Xyne
Hi Magnus,
Everything seems to be working as expected. Have you overcome the problems of ensuring a secure custody chain?
I'm not quite satisfied with it, but just keeping a subkey for signing on kiwilight (where I build), will have to do.
Also, could you send me a copy of the ArchHaskell key signed with your other key (0xAB4DFBA4)?
Will do, as soon as I've signed the "real" repos. /M -- Magnus Therning OpenPGP: 0xAB4DFBA4 email: magnus@therning.org jabber: magnus@therning.org twitter: magthe http://therning.org/magnus

On Fri, Dec 28, 2012 at 12:03:48PM +0100, Magnus Therning wrote:
On Fri, Dec 28, 2012 at 1:25 AM, Xyne
wrote: Hi Magnus,
Everything seems to be working as expected. Have you overcome the problems of ensuring a secure custody chain?
I'm not quite satisfied with it, but just keeping a subkey for signing on kiwilight (where I build), will have to do.
Also, could you send me a copy of the ArchHaskell key signed with your other key (0xAB4DFBA4)?
Will do, as soon as I've signed the "real" repos.
I've now signed the official repos, both x86_64 and i686. The signing will work whether you access it as [haskell] or [haskell-core]. I've also signed the database, which means the following kind of entry will now work: [haskell-core] SigLevel = Required TrustedOnly Server = http://www.kiwilight.com/haskell/core/$arch The key has been uploaded to the server hkp://pgp.mit.edu: 4209170B Oh, by the way, I've been putting up deltas for a while too, even though every delta seems to be larger than the original :) /M -- Magnus Therning OpenPGP: 0xAB4DFBA4 email: magnus@therning.org jabber: magnus@therning.org twitter: magthe http://therning.org/magnus Perl is another example of filling a tiny, short-term need, and then being a real problem in the longer term. -- Alan Kay

I've now signed the official repos, both x86_64 and i686. The signing will work whether you access it as [haskell] or [haskell-core]. I've also signed the database, which means the following kind of entry will now work:
[haskell-core] SigLevel = Required TrustedOnly Server = http://www.kiwilight.com/haskell/core/$arch
Is kiwilight.com the new default server? At the moment I still use xsounds.org... Thank you for the job! Fabio

On Wed, Jan 9, 2013 at 12:54 PM, Fabio Riga
I've now signed the official repos, both x86_64 and i686. The signing will work whether you access it as [haskell] or [haskell-core]. I've also signed the database, which means the following kind of entry will now work:
[haskell-core] SigLevel = Required TrustedOnly Server = http://www.kiwilight.com/haskell/core/$arch
Is kiwilight.com the new default server? At the moment I still use xsounds.org...
No, it just happens to be the one I use, since it's also the one where I compile. All signatures have been pushed to xsounds.org as well. /M -- Magnus Therning OpenPGP: 0xAB4DFBA4 email: magnus@therning.org jabber: magnus@therning.org twitter: magthe http://therning.org/magnus

On Tue, Jan 08, 2013 at 11:40:06PM +0100, Magnus Therning wrote:
On Fri, Dec 28, 2012 at 12:03:48PM +0100, Magnus Therning wrote: Oh, by the way, I've been putting up deltas for a while too, even though every delta seems to be larger than the original :)
I can report that there are occasions where the generated deltas actually are smaller than the original. For the first time ever since I started putting deltas on [haskell-core] have I now seen it used :) ... applying deltas... generating ghc-mod-1.11.3-3-x86_64.pkg.tar.xz with ghc-mod-1.11.3-2_to_1.11.3-3-x86_64.delta... success! generating haskell-pandoc-1.9.4.5-13-x86_64.pkg.tar.xz with haskell-pandoc-1.9.4.5-12_to_1.9.4.5-13-x86_64.delta... success! .... Nice to see it working. /M -- Magnus Therning OpenPGP: 0xAB4DFBA4 email: magnus@therning.org jabber: magnus@therning.org twitter: magthe http://therning.org/magnus I invented the term Object-Oriented, and I can tell you I did not have C++ in mind. -- Alan Kay

On Thu, Dec 27, 2012 at 12:06:48AM +0100, Magnus Therning wrote:
Hi all,
I've finally gotten around to looking at signing repos and have put a signed copy of [haskell-core] on kiwilight. I'd appreciate someone else testing it before I take the step to sign [haskell-core] itself. Here's the config I use at the moment:
[haskell-test] SigLevel = Required TrustedOnly Server = http://www.kiwilight.com/haskell/test
Since the main repo is signed now I have removed this test repo. /M -- Magnus Therning OpenPGP: 0xAB4DFBA4 email: magnus@therning.org jabber: magnus@therning.org twitter: magthe http://therning.org/magnus Most software today is very much like an Egyptian pyramid with millions of bricks piled on top of each other, with no structural integrity, but just done by brute force and thousands of slaves. -- Alan Kay
participants (3)
-
Fabio Riga
-
Magnus Therning
-
Xyne