grant-olson / rubygems-openpgp

This allows you to cryptographically sign ruby gems, so that a user can later verify that they've downloaded a copy that hasn't been tampered with or hacked.
http://www.rubygems-openpgp-ca.org
Other
32 stars 4 forks source link

--get-key should be implicit #35

Open grant-olson opened 10 years ago

grant-olson commented 10 years ago

I originally explicitly required --get-key so that we wouldn't silently download keys when we only had verification without trust. In that case it was useful to know that you didn't previously have the key. With trust, it should be fine to silently retrieve the key since we still won't past the trust check.