Get the latest tech news

The Linux Kernel's PGP Web of Trust


kernel's development process makes use of PGP. The most relevant part here is that subsystem maintainers are supposed to use signed tags in their pull requests to Linus Torvalds.

The most relevant part here is that subsystem maintainers are supposed to use signed tags in their pull requests to Linus Torvalds. As the concept of keyservers is considered broken, Konstantin Ryabitsev maintains a collection of relevant keys in a git repository. However there is a problem on the horizon: GnuPG 2.4.x started to reject third-party key signatures using the SHA-1 hash algorithm.

Get the Android app

Or read this on Hacker News

Read more on:

Photo of linux kernel

linux kernel

Photo of trust

trust

Photo of PGP

PGP

Related news:

News photo

Loongson To Up Linux Kernel Limit To 2,048 LoongArch CPU Cores

News photo

Intel Introducing QAT "GEN6" Driver To The Linux Kernel

News photo

Deferred THP Insertion Nearing The Linux Kernel To Help Avoid Memory Waste