<feed xmlns='http://www.w3.org/2005/Atom'>
<title>src/etc/pkg, branch main</title>
<subtitle>FreeBSD source tree</subtitle>
<link rel='alternate' type='text/html' href='http://cgit.freebsd.org/src/'/>
<entry>
<title>Move pkg/FreeBSD.conf to usr.sbin/pkg/</title>
<updated>2018-07-31T16:42:03+00:00</updated>
<author>
<name>Brad Davis</name>
<email>brd@FreeBSD.org</email>
</author>
<published>2018-07-31T16:42:03+00:00</published>
<link rel='alternate' type='text/html' href='http://cgit.freebsd.org/src/commit/?id=5836319ae6f19d7804848f6ea0d46e1b810ddf58'/>
<id>5836319ae6f19d7804848f6ea0d46e1b810ddf58</id>
<content type='text'>
Approved by:	bapt (mentor)
Differential Revision:	https://reviews.freebsd.org/D16491
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Approved by:	bapt (mentor)
Differential Revision:	https://reviews.freebsd.org/D16491
</pre>
</div>
</content>
</entry>
<entry>
<title>Give hint on how to disable the default repository.</title>
<updated>2014-03-30T15:24:17+00:00</updated>
<author>
<name>Bryan Drewery</name>
<email>bdrewery@FreeBSD.org</email>
</author>
<published>2014-03-30T15:24:17+00:00</published>
<link rel='alternate' type='text/html' href='http://cgit.freebsd.org/src/commit/?id=f9374f07245a525f6fe0f516f17d204f7f74fabc'/>
<id>f9374f07245a525f6fe0f516f17d204f7f74fabc</id>
<content type='text'>
Discussed with:	bapt
MFC after:	instantly (preparing EN)
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Discussed with:	bapt
MFC after:	instantly (preparing EN)
</pre>
</div>
</content>
</entry>
<entry>
<title>Enabled should be a boolean, not a string</title>
<updated>2013-11-16T15:54:46+00:00</updated>
<author>
<name>Baptiste Daroussin</name>
<email>bapt@FreeBSD.org</email>
</author>
<published>2013-11-16T15:54:46+00:00</published>
<link rel='alternate' type='text/html' href='http://cgit.freebsd.org/src/commit/?id=63af4435d97dfaaf910eb8d18eb14988e2c93bbe'/>
<id>63af4435d97dfaaf910eb8d18eb14988e2c93bbe</id>
<content type='text'>
MFC after:	2 days
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
MFC after:	2 days
</pre>
</div>
</content>
</entry>
<entry>
<title>Use proper capitalization for FreeBSD.org</title>
<updated>2013-11-05T02:22:04+00:00</updated>
<author>
<name>Bryan Drewery</name>
<email>bdrewery@FreeBSD.org</email>
</author>
<published>2013-11-05T02:22:04+00:00</published>
<link rel='alternate' type='text/html' href='http://cgit.freebsd.org/src/commit/?id=cecc0167918b9dd768288bae00c6ca3f6753446a'/>
<id>cecc0167918b9dd768288bae00c6ca3f6753446a</id>
<content type='text'>
Approved by:	bapt
MFC after:	2 days
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Approved by:	bapt
MFC after:	2 days
</pre>
</div>
</content>
</entry>
<entry>
<title>Enable fingerprint checking as the currently known</title>
<updated>2013-11-05T02:20:49+00:00</updated>
<author>
<name>Bryan Drewery</name>
<email>bdrewery@FreeBSD.org</email>
</author>
<published>2013-11-05T02:20:49+00:00</published>
<link rel='alternate' type='text/html' href='http://cgit.freebsd.org/src/commit/?id=5ca9b3ca8eb574df9d70f2a5b782fb6d49b05282'/>
<id>5ca9b3ca8eb574df9d70f2a5b782fb6d49b05282</id>
<content type='text'>
fingerprint has an uploaded signature on all mirrors.

Approved by:	bapt
MFC after:	2 days
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
fingerprint has an uploaded signature on all mirrors.

Approved by:	bapt
MFC after:	2 days
</pre>
</div>
</content>
</entry>
<entry>
<title>Move /etc/keys to /usr/share/keys where users are less likely to modify them.</title>
<updated>2013-10-29T15:07:54+00:00</updated>
<author>
<name>Bryan Drewery</name>
<email>bdrewery@FreeBSD.org</email>
</author>
<published>2013-10-29T15:07:54+00:00</published>
<link rel='alternate' type='text/html' href='http://cgit.freebsd.org/src/commit/?id=8d20be1e22095c27faf8fe8b2f0d089739cc742e'/>
<id>8d20be1e22095c27faf8fe8b2f0d089739cc742e</id>
<content type='text'>
Requested by:	secteam (cperciva, des)
Approved by:	bapt
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Requested by:	secteam (cperciva, des)
Approved by:	bapt
</pre>
</div>
</content>
</entry>
<entry>
<title>Disable fingerprint checking for now as the pkg repository mirrors will</title>
<updated>2013-10-26T14:19:57+00:00</updated>
<author>
<name>Bryan Drewery</name>
<email>bdrewery@FreeBSD.org</email>
</author>
<published>2013-10-26T14:19:57+00:00</published>
<link rel='alternate' type='text/html' href='http://cgit.freebsd.org/src/commit/?id=914d05f14e1e8b76ea41db3c526f436f86c586b5'/>
<id>914d05f14e1e8b76ea41db3c526f436f86c586b5</id>
<content type='text'>
not receive the signature until later this week.

Approved by:	bapt
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
not receive the signature until later this week.

Approved by:	bapt
</pre>
</div>
</content>
</entry>
<entry>
<title>Support checking signature for pkg bootstrap.</title>
<updated>2013-10-26T03:43:02+00:00</updated>
<author>
<name>Bryan Drewery</name>
<email>bdrewery@FreeBSD.org</email>
</author>
<published>2013-10-26T03:43:02+00:00</published>
<link rel='alternate' type='text/html' href='http://cgit.freebsd.org/src/commit/?id=f12db248e7103a02ef63683a5d3054a5d88e9a5d'/>
<id>f12db248e7103a02ef63683a5d3054a5d88e9a5d</id>
<content type='text'>
If the pkg.conf is configured with SIGNATURE_TYPE: FINGERPRINTS,
and FINGERPRINTS: /etc/keys/pkg then a pkg.sig file is fetched along
with pkg.txz. The signature contains the signature provided by the
signing server, and the public key. The .sig is the exact output
from the signing server in the following format:

  SIGNATURE
  &lt;openssl signed&gt;
  CERT
  &lt;rsa public key&gt;
  END

The signature is verified with the following logic:

 - If the .sig file is missing, it fails.
 - If the .sig doesn't validate, it fails.
 - If the public key in the .sig is not in the known trusted fingerprints,
   it fails.
 - If the public key is in the revoked key list, it fails.

Approved by:	bapt
MFC after:	2 days
Discussed by:	bapt with des, jonathan, gavin
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
If the pkg.conf is configured with SIGNATURE_TYPE: FINGERPRINTS,
and FINGERPRINTS: /etc/keys/pkg then a pkg.sig file is fetched along
with pkg.txz. The signature contains the signature provided by the
signing server, and the public key. The .sig is the exact output
from the signing server in the following format:

  SIGNATURE
  &lt;openssl signed&gt;
  CERT
  &lt;rsa public key&gt;
  END

The signature is verified with the following logic:

 - If the .sig file is missing, it fails.
 - If the .sig doesn't validate, it fails.
 - If the public key in the .sig is not in the known trusted fingerprints,
   it fails.
 - If the public key is in the revoked key list, it fails.

Approved by:	bapt
MFC after:	2 days
Discussed by:	bapt with des, jonathan, gavin
</pre>
</div>
</content>
</entry>
<entry>
<title>Add support for reading configuration files from /etc/pkg.</title>
<updated>2013-10-26T03:31:05+00:00</updated>
<author>
<name>Bryan Drewery</name>
<email>bdrewery@FreeBSD.org</email>
</author>
<published>2013-10-26T03:31:05+00:00</published>
<link rel='alternate' type='text/html' href='http://cgit.freebsd.org/src/commit/?id=bc5e9ac08d8771b98cbde59775ec2dc776fb1ed0'/>
<id>bc5e9ac08d8771b98cbde59775ec2dc776fb1ed0</id>
<content type='text'>
For now only /etc/pkg/FreeBSD.conf is supported. Its style is:

Repo: {
   URL: "...",
   MIRROR_TYPE: "...",
   ...
}

The configuration will be read from /usr/local/etc/pkg.conf if exists,
otherwise /etc/pkg/FreeBSD.conf

Approved by:	bapt
MFC after: 	2 days
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
For now only /etc/pkg/FreeBSD.conf is supported. Its style is:

Repo: {
   URL: "...",
   MIRROR_TYPE: "...",
   ...
}

The configuration will be read from /usr/local/etc/pkg.conf if exists,
otherwise /etc/pkg/FreeBSD.conf

Approved by:	bapt
MFC after: 	2 days
</pre>
</div>
</content>
</entry>
</feed>
