conexversion

Establish trust in community repositories

Conex is a utility for verify and attest release integrity and authenticity of community repositories through the use of cryptographic signatures (RSA-PSS-SHA256). It is based on the update framework, especially on their CCS 2010 paper, and adapted to the requirements of the opam repository.

The developer sign their release checksums and build instructions. A quorum (with a configurable threshold) of repository maintainers signs the package name to developer key relation. These repository maintainers are enrolled by a quorum of offline root keys.

The TUF spec has a good overview of attacks and threat model, both of which are shared by conex.

AuthorHannes Mehnert <hannes@mehnert.org>
LicenseBSD-2-Clause
Published
Homepagehttps://github.com/hannesm/conex
Issue Trackerhttps://github.com/hannesm/conex/issues
MaintainerHannes Mehnert <hannes@mehnert.org>
Dependencies
Source [http] https://github.com/hannesm/conex/releases/download/0.10.0/conex-0.10.0.tbz
md5=39cdb4e3a550703e61b2f56d20323fdd
Edithttps://github.com/ocaml/opam-repository/tree/master/packages/conex/conex.0.10.0/opam
Required by