You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Seeing md5s on the downloads is nice, but I'm really uncomfortable with downloads which aren't digitally signed by the author. I want to know that the software I'm recommending for production has had reasonable precautions taken to prevent tampering. Signing is so easy these days, I'm surprised they aren't already.
What are your plans regarding signing downloads?
The text was updated successfully, but these errors were encountered:
@binaryphile The packages downloaded through the repository (repos.influxdata.com) are already signed if you need something in the short-term. In the longer term, we are currently revamping our build process, but I'll add this as a feature request to offer signed packages through the Downloads page as well.
rossmcdonald
changed the title
Signatures on downloads
[feature request] Add ability to sign packages built with packaging script / Offer signed packages on Downloads page
Dec 15, 2015
Where you should see a GPG message based on whether the signature was verified, such as:
gpg: Signature made Tue Mar 29 19:03:59 2016 UTC using RSA key ID 2582E0C5
gpg: Good signature from "InfluxDB Packaging Service <support@influxdb.com>"
Seeing md5s on the downloads is nice, but I'm really uncomfortable with downloads which aren't digitally signed by the author. I want to know that the software I'm recommending for production has had reasonable precautions taken to prevent tampering. Signing is so easy these days, I'm surprised they aren't already.
What are your plans regarding signing downloads?
The text was updated successfully, but these errors were encountered: