From owner-freebsd-questions@FreeBSD.ORG Sun Mar 9 03:50:21 2014 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [8.8.178.115]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 35B12F72 for ; Sun, 9 Mar 2014 03:50:21 +0000 (UTC) Received: from mail-vc0-x233.google.com (mail-vc0-x233.google.com [IPv6:2607:f8b0:400c:c03::233]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by mx1.freebsd.org (Postfix) with ESMTPS id EA5DDC61 for ; Sun, 9 Mar 2014 03:50:20 +0000 (UTC) Received: by mail-vc0-f179.google.com with SMTP id ij19so5271124vcb.38 for ; Sat, 08 Mar 2014 19:50:20 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :content-type; bh=X5pzb5WOQX819fT48bwXru6yAao47fWp4WM5TWPaVIc=; b=k8ijBI5Nsyw6exXWwb+YniYZe3FwFxGfPLaBcXnPniyjhhHb4Em6Rv970lxYioRQwu hpv5nhDJOIvaGKnt6fXdHi7l+YlUQ3Unp003gJ/QtSpqU78k5P/COKzRKrwKY3WlLxKP E0r9DN4s3Vug27cFFU59nFyRbjObR67lKyKcsjZ32uNGw4Nm8er50haJwfN19YZJVLjQ o0PSk5FI79HWIm15wNyr66Qdi496O0Vhl0Pyjs1gIxdtVAdb737K5h/pSmBNDiiX2p4u eWoOlLXra0Kb/rROdah2Y7IxekUctAhcEqY9h7rmVCJDWcLXvhFC33kRKj65EftSZ4c0 IwlA== MIME-Version: 1.0 X-Received: by 10.52.251.199 with SMTP id zm7mr9338271vdc.21.1394337020070; Sat, 08 Mar 2014 19:50:20 -0800 (PST) Received: by 10.220.106.199 with HTTP; Sat, 8 Mar 2014 19:50:19 -0800 (PST) In-Reply-To: References: Date: Sat, 8 Mar 2014 22:50:19 -0500 Message-ID: Subject: Re: Secure Infrastructure [Crypto signed ISO images] From: grarpamp To: freebsd-questions@freebsd.org Content-Type: text/plain; charset=UTF-8 X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.17 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 09 Mar 2014 03:50:21 -0000 > What about the processor microcode, device(s) firmware, BIOS, extension > ROM(s), ... , installed software [meaning upstream port source]... of the > machines used to serve the repository and do the builds? That is obviously outside the scope of the project to change/control. Certainly you knew that when posting, and similarly why I didn't include it. > boot managers, boot loaders, kernels, operating systems... This is within said scope.