OpenBSD does something like this. In the current release, they provide the public keys for the next release. After trust-on-first-use it's a never-ending cycle.
I call it trust-on-first-use because I didn't verify the initial signatures. Hmmm..
I call it trust-on-first-use because I didn't verify the initial signatures. Hmmm..
No comments yet.