Hi,
The daily modsecurity rules tarballs used to have a .asc file available with them with a PGP signature for the file, but now I can't find that .asc file (I use it to check that the modsec rules are valid). Are they intentionally no longer signed?
Thanks,
David
PGP signatures for ModSec rules?
-
- New Forum User
- Posts: 1
- Joined: Mon Apr 25, 2016 9:25 pm
- Location: Auckland
-
- Atomicorp Staff - Site Admin
- Posts: 8355
- Joined: Wed Dec 31, 1969 8:00 pm
- Location: earth
- Contact:
Re: PGP signatures for ModSec rules?
For the moment yes they are disabled. For infrastructure/update speed reasons the archives are generated on the mirrors. We'll probably augment this with sha512 hashes like we do with the installers.