* added GPG signature verification via gpgme (thanks Pat Volkerding for
adding gpgme to -current) * Updated downloading in libslapt for better notification. This also resulted in some simplification in code. Removed unused DEBUG ifdefs. Removed deprecated translation strings. Added error condition strings and slapt_strerror() function. New translation strings. Bumped to 0.9.12.
@@ -53,6 +53,7 @@ Frequently Asked Questions:
50. What about mirror fall back / fail-over ?
51. How do I install a kernel rather than upgrade the existing kernel?
52. What are the relationships of CHECKSUMS.md5, PACKAGES.TXT and package_data?
+53. Does slapt-get support the GPG/PGP signature verification?
@@ -1167,3 +1168,15 @@ Frequently Asked Questions:
source and continue.
+53. Does slapt-get support the GPG/PGP signature verification?
+ Yes, as of 0.9.12 slapt-get can be built with gpgme support that allows
+ slapt-get to verify the signature of the CHECKSUMS file on each mirror.
+ This requires the presence of the signature file and the GPG-KEY file on
+ the package source. The GPG-KEY is imported into the local keychain using
+ the --add-keys option. When running --update, the signature file for the
+ CHECKSUMS listing is downloaded and verification is attempted. If the key
+ is not present slapt-get mentions this and continues on. slapt-get only halts
+ if verification failed.