Skip to content

Commit c7def4d

Browse files
committed
Implement PGP signature verification and SHA256 checks.
This will use PGP to verify the client info file, then use the checksums from that file to verify the files it references after they are downloaded. This is intended to mitigate main-in-the-middle attacks against Quicklisp bootstrapping. More work remains to be done on the client side.
1 parent e83ff25 commit c7def4d

File tree

1 file changed

+1381
-9
lines changed

1 file changed

+1381
-9
lines changed

0 commit comments

Comments
 (0)