Arch Linux and Valve Collaboration
https://lists.archlinux.org/archives/list/[email protected]/thread/RIZSKIBDSLY4S5J2E2STNP5DH4XZGJMR/
Arch Linux and Valve Collaboration
https://lists.archlinux.org/archives/list/[email protected]/thread/RIZSKIBDSLY4S5J2E2STNP5DH4XZGJMR/
@TTimo well OBS can also do arch building :)
And not too long ago we also had k8s moving to OBS for similar requirements.
It is kinda fun to think about how we went from doing gaming stuff to Linux things. And then that helps improving gaming on Linux. I still remember chatting with you about asset management for games a long long time ago :)
@darix I did start at id doing Linux things. And that did catch up to me again. I miss doing game development though. Maybe I find my way back to shipping games in the not too distant future.
Are you still in Dallas these days?
What you are proposing doesn't exist.
The signing enclaves would move the package signing from the developer keys to a central signing key. It would avoid the current problem where users have issues with our developer keys because of outdated systems.
We could also support Secure Boot with a signed shim, but this is further down the pipeline.
Basically what Morten wrote above.
Whether and to what extend Valve uses what we do is out of our hands. Generally speaking, we do hope to create broadly reusable code (as always) though.
More details about the (work on the) signing service can be gotten via the following link:
https://chaos.social/@dvzrv/113204676874021796
My talk "Boring Infrastructure: Building a secure signing environment" from #asg2024 is online: https://media.ccc.de/v/all-systems-go-2024-263-boring-infrastructure-building-a-secure-signing-environment You can find the slides for it at: https://pkgbuild.com/~dvzrv/presentations/all-systems-go-2024/ #AllSystemsGo #OpenPGP #DigitalSignature #Signing #Berlin #Linux #ArchLinux #Signstar