0149-cache-key-rotation: add some alternatives

This commit is contained in:
Vladimír Čunát 2023-05-28 08:37:19 +02:00
parent 7681874854
commit 407a35e6e9
No known key found for this signature in database
GPG key ID: E747DF1F9575A3AA

View file

@ -58,7 +58,13 @@ Why should we *not* do this?
# Alternatives
[alternatives]: #alternatives
What other designs have been considered? What is the impact of not doing this?
- change nothing, obviously
- also resign old `*.narinfo`. Maybe it's not too hard.
It would help people wanting ot use old builds.
- double-sign `*.narinfo` for some time. (also not an exclusive alternative)
I don't know if consumers support multiple signatures.
It doesn't seem to give us significant advantage though;
acceptance of multiple keys seems more advantageous.
# Unresolved questions
[unresolved]: #unresolved-questions