Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Mon, 19 Aug 2013 21:19:41 -0400
From: "Eric H. Christensen" <echriste@...hat.com>
To: oss-security@...ts.openwall.com, kseifried@...hat.com
Cc: security@...tgresql.org
Subject: Re: PostgreSQL insecure install via yum (multiple
 problems)

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On Mon, Aug 19, 2013 at 06:58:22PM -0600, Kurt Seifried wrote:
> Signing RPM's isn't very useful if you never make the signing key
> available!

You mean like this:  http://keys.fedoraproject.org/pks/lookup?search=0x442df0f8&op=vindex

I'm pretty sure pgp.mit.edu isn't the best source for PGP keys any longer, unfortunately.

- -- Eric

- --------------------------------------------------
Eric "Sparks" Christensen
Red Hat, Inc - Product Security Team

sparks@...hat.com - sparks@...oraproject.org
097C 82C3 52DF C64A 50C2  E3A3 8076 ABDE 024B B3D1
- --------------------------------------------------
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.14 (GNU/Linux)

iQGcBAEBCgAGBQJSEsQqAAoJEB/kgVGp2CYvhFAL/3vUyx8NgCyik42NiJKqOlAe
yarq7tz6r3CoIxNkcl6LkOpNfsNK6/eSs3K5/ZngUXJX0fIW+jISAPU8TSKLY9AG
nkEMAJnMpDwwzLbOjrOpSJglFsb4pj+A/q3WTD09HvocJqZXyYKbQK3li5nsj6qR
TVlBYchjKs3yRBZQdobwK7YVkyQrZIB8a7bFZhyH5OUKHOsWh6cae/7bpkJ55kX/
8n0j+OP1rAMhPXior40soJAmG/XrVQsiuw4GAJ8eGoc1bGybcBZ5SarRTrbq2s7q
DQaQZn9HfwCeXoHODYyJj6Pp77l9qKKB72BF+2BDDLmI8lsI681xmMW3On7rCoP6
PbLkxUHWicO9KtyNg1WYW8wHv0HiwnLPhNNilzlNLoTBBGRIZr6Bb0+Nq1uD1uUD
E4GymQfIyYRNvowyyFGlh/2fMY5tpFMSR6gtu50tZpaSyhKS0bjzYM68jRX6YCW8
YyOhcL7uKKenZESWcPHTgq8Z/Yd4rJs0zRrKlXVzsA==
=Y/N1
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.