Subject: Re: signed binary pkgs [was: Re: BPG call for use cases]
To: Jason Thorpe <>
From: Malcolm Herbert <>
List: tech-security
Date: 07/26/2005 14:46:56
On Mon, Jul 25, 2005 at 09:20:28PM -0700, Jason Thorpe wrote:
|On Jul 25, 2005, at 5:20 PM, John Kohl wrote:
|>separate mounted file system).  If we're talking about serious  
|>rework of
|>packaging for signing, how about switching to a zip or similar archive
|>format with random access to members?
|I would certainly not object to such a change.

I seem to recall that the GNU tar group were looking to do gzip
compression of individual files before being placed in an archive stream
rather than after it as this would have provided better support for
things like backups via rsync, but I don't know how much progress they
made in this area ...

it doesn't get you random access though, I grant you ... :)

