<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style>
</head>
<body dir="ltr">
<div id="divtagdefaultwrapper" style="font-size:12pt;color:#000000;font-family:Calibri,Helvetica,sans-serif;" dir="ltr">
<p>Hello,</p>
<p><br>
</p>
<p>It would be great if the important commits, especially those corresponding to tags, were signed using a long term&nbsp;keys (ex: GPG, SSH or&nbsp;X.509, you have the choice since&nbsp;git supports many formats) with the corresponding public keys published on Lustre web
 site and their fingerprints on this mailing list for example. This would allow every user to have a better confidence in the integrity of the associated code and comply more with the end-to-end principle as the private keys would be kept preciously by the
 developers.</p>
<p><br>
</p>
<p>It is the same thing with&nbsp;the&nbsp;RPMs and&nbsp;DEBs&nbsp; packages&nbsp;distributed over the whamcloud repository (<a href="https://downloads.whamcloud.com/public/lustre/" class="OWAAutoLink" id="LPlnk437213">https://downloads.whamcloud.com/public/lustre/</a>) except that
 the choice of the key system is limited to GPG in this case. As you know it is the common practice to associate a public key with every remote repository to verify the authenticity of every downloaded package before installation (but it is not yet done on
 this repository).</p>
<p><br>
</p>
<p>Performing downloads or &quot;git&quot; access over &quot;https&quot; is better than nothing but the guaranty of integrity is way better if&nbsp;done by signatures closer to the original&nbsp;authors.<br>
<br>
Signing keys could even be held&nbsp;on hardware devices such as Yubikeys as this would&nbsp;be both very secure and&nbsp;convenient for developers.</p>
<p><br>
</p>
<p>Please consider this suggestion, I am sure it would satisfy many users.</p>
<p><br>
</p>
<p>Thanks,</p>
<p><br>
</p>
<p>Martin Audet</p>
</div>
</body>
</html>