Weird downloading problem

Mauricio Teixeira mteixeira at webset.net
Sat Feb 16 02:06:45 PST 2008


On 02/16/2008 08:02 AM, Patryk Zawadzki wrote:
> No, the file was not modified in between and our packages are all
> signed so no m-i-t-m attack is really possible without rpm
> complaining.

Smart does not know that, and won't trust anything that is not written 
in the metadata, that's my point.

Also, current version of Smart does not check for GPG, so we need to 
find something else to trust on.

If it's your own repo, go to the server and run createrepo again. You 
will see everything will work just fine.

-- 
% Mauricio Teixeira (netmask) | Sao Paulo/SP/BR      %
% mteixeira{a}webset{d}net    | http://smartpm.org   %
% http://mteixeira.webset.net | http://pmping.sf.net %

NOTE: This is my personal e-mail account. I do NOT use
it to speak for my employer or any of my co-workers.



More information about the Smart mailing list