[2004] in Kerberos_V5_Development
Re: Final draft of build instructions of krb5 1.0
daemon@ATHENA.MIT.EDU (Marc Horowitz)
Sat Nov 23 01:55:35 1996
To: "Theodore Y. Ts'o" <tytso@MIT.EDU>
Cc: krbdev@MIT.EDU
From: Marc Horowitz <marc@cygnus.com>
Date: 23 Nov 1996 01:55:30 -0500
In-Reply-To: "Theodore Y. Ts'o"'s message of Sat, 23 Nov 1996 00:48:59 -0500
"Theodore Y. Ts'o" <tytso@MIT.EDU> writes:
>> o Create a detached PGP signature of the distribution file:
>>
>> % pgp -sab /tmp/krb5-1.0-<platform>.tgz
>>
>> o Prepend filled out build information template to the beginning of the
>> PGP signature file (krb5-1.0-<platform>.asc)
If you do this, then the build information is not bound to the tarball
in any way. I think the build information should be in the tarball,
too, so that it is part of the signature. This makes the build info
in the .asc file advisory, and the info in the tarball authoritative.
The other option is not to have the build into in the .asc file at all.
Marc