Skip to content

Stabilise nix store verify #8917

@fricklerhandwerk

Description

@fricklerhandwerk

This implements NixOS/rfcs#136. This issue is agreed-upon by the @NixOS/nix-team

Required changes:

  • needs documentation on the default number of signatures required
    • also should say why it's important: copying a closure to a remote system loses the "ultimately trusted" bit, so before deploying, one will want to make sure it's fully signed
  • signatures should be compared by key contents only, excluding names

Metadata

Metadata

Assignees

No one assigned

    Labels

    RFCRelated to an accepted RFCidea approvedThe given proposal has been discussed and approved by the Nix team. An implementation is welcome.new-cliRelating to the "nix" command

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions