5 ms·
Individual package signing does seem more straightforward. But, signing a file containing a list of hashes of the individual package files, as Debian does, acc
by sillystuff 3y ago
Individual package signing does seem more straightforward. But, signing a file containing a list of hashes of the individual package files, as Debian does, accomplishes the same verification of package integrity when installing from a repo.
I'm guessing the genesis was since Debian already checked package hashes to ensure no download issues, adding a cryptographic signature to the file containing those hashes was an easy, minimal change that would not break existing clients that didn't know to check it.
Off repo is a use case that IMO should be strongly discouraged (as should adding random repos), but to your point, if you have no choice, a per-package sig would be useful.