Join GitHub today
GitHub is home to over 31 million developers working together to host and review code, manage projects, and build software together.
Sign upSign and validate signatures of rustup-setup #242
Comments
This comment has been minimized.
This comment has been minimized.
|
We might also create a new key just for rustup instead of messing with the rust key. |
brson
added
the
security
label
May 12, 2016
brson
referenced this issue
Aug 22, 2016
Closed
rustup.sh and underlying binaries authentication #16442
jonathanKingston
referenced this issue
Jan 8, 2017
Open
Consider providing an asc file for gpg checking for rustup-init #915
Diggsey
added this to Build
in Issue Categorisation
May 4, 2017
This comment has been minimized.
This comment has been minimized.
heartsucker
commented
Jul 29, 2017
|
Just noting here for completeness that this will be covered by using TUF as it requires mandatory signatures. See #241. |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
brson commentedApr 1, 2016
We need to sign rustup-setup and validate them on self-update. Probably we can create a new subkey of the existing signing key and give the secrets to travis and appveyor.
This should use the same crypto as we use for rust builds.