Re: Secure and verified way to get the Postgresql RPM's

From: Devrim Gündüz <devrim(at)gunduz(dot)org>
To: Luitzen van Gorkum <luitzen(dot)van(dot)gorkum(at)gmail(dot)com>
Cc: pgsql-pkg-yum(at)postgresql(dot)org
Subject: Re: Secure and verified way to get the Postgresql RPM's
Date: 2014-10-22 21:07:49
Message-ID: 1414012069.13508.6.camel@asus-laptop-03.gunduz.org
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-pkg-yum


Hi,

This is currently in discussion with infrastructure team, to serve the
RPMs on https. I will keep you updated.

Regards, Devrim
On Mon, 2014-10-20 at 11:40 +0200, Luitzen van Gorkum wrote:
> LS,
>
> My company has the policy only to use secure verified software from the
> Internet. Therefore I've two questions for you:
>
> 1) Is the a secure way to get the GPG key for the postgresql software?
> Currently this is only down-loadable from your public website without a
> way to verify this is indeed the one and only postgresql source.
>
> 2) Can you guarantee that software from your unsigned website is indeed
> the one and only software you provide?
>
> Kind regards, Luitzen van Gorkum
>
>
>

--
Devrim GÜNDÜZ
Principal Systems Engineer @ EnterpriseDB: http://www.enterprisedb.com
PostgreSQL Danışmanı/Consultant, Red Hat Certified Engineer
Twitter: @DevrimGunduz , @DevrimGunduzTR

In response to

Browse pgsql-pkg-yum by date

  From Date Subject
Next Message Devrim Gündüz 2014-10-27 08:19:15 Re: Centos 5 postgis2_92 packages
Previous Message Luitzen van Gorkum 2014-10-20 09:40:51 Secure and verified way to get the Postgresql RPM's