[Distutils] Python people want CPAN and how the latter came about

Tres Seaver tseaver at palladion.com
Fri Dec 25 06:12:55 CET 2009

Hash: SHA1

Tarek Ziadé wrote:
> On Thu, Dec 24, 2009 at 11:20 AM, kiorky <kiorky at cryptelium.net> wrote:
> [..]
>>> That said, some people have expressed the desire to be able to
>>> interact with PyPI through SSH so they could drop the basic
>>> authentication and use their keys when registering/uploading.
>>> But that was not related to the size of files.
>> Both i think, it's easier to use the transfer programs that we are used to use
>> to transfer things.
>> And ssh is damn good for that, easy to setup, secure and so on.
>> But it's only butter, in fact i am just happy with sdist upload.
> Although SSH is quite a heavy development on PyPI side, it means we
> would have to implement
> an SSH server. (like Zope did I think for their development server,
> using Paramiko IIRC)

cvs.zope.org / svn.zope.org (same machine) run a stock sshd:  they use
the "command=" prefix on users' pubkeys to limit what that key can be
used to do (only SVN / CVS operations for any non-admin users).

- --
Tres Seaver          +1 540-429-0999          tseaver at palladion.com
Palladion Software   "Excellence by Design"    http://palladion.com
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org


More information about the Distutils-SIG mailing list