kernel.org no longer centrally signs submissions
kernel.org no longer centrally signs submissions
Posted Nov 9, 2011 0:24 UTC (Wed) by jimparis (guest, #38647)In reply to: kernel.org no longer centrally signs submissions by raven667
Parent article: KS2011: Kernel.org report
It seems the argument is that, as far as trust goes, "you downloaded this from kernel.org" is exactly the same assurance as the old "this was signed by kernel.org". That may be true (if SSL was used for the download), but it still seems that no harm would be done by also adding that automatic signature. Then SSL wouldn't be necessary, and you could verify that it passed through kernel.org even if you downloaded it from another site or mirror.