Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Move package trust into signing of NARs #75

Open
soupglasses opened this issue Aug 24, 2023 · 0 comments
Open

Move package trust into signing of NARs #75

soupglasses opened this issue Aug 24, 2023 · 0 comments

Comments

@soupglasses
Copy link
Owner

Currently, a use of root, sudo and trusted-users configuration inside nix is applied to bypass signature verification of built derivations and nix archives (NARs).

Figure out an effective method to generate and apply these. Use sops to avoid having multiple/loose keys.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant