[Distutils] Python people want CPAN and how the latter came about

Tres Seaver tseaver at palladion.com
Fri Dec 25 06:12:55 CET 2009


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Tarek Ziadé wrote:
> On Thu, Dec 24, 2009 at 11:20 AM, kiorky <kiorky at cryptelium.net> wrote:
> [..]
>>> That said, some people have expressed the desire to be able to
>>> interact with PyPI through SSH so they could drop the basic
>>> authentication and use their keys when registering/uploading.
>>> But that was not related to the size of files.
>>>
>> Both i think, it's easier to use the transfer programs that we are used to use
>> to transfer things.
>> And ssh is damn good for that, easy to setup, secure and so on.
>>
>> But it's only butter, in fact i am just happy with sdist upload.
> 
> Although SSH is quite a heavy development on PyPI side, it means we
> would have to implement
> an SSH server. (like Zope did I think for their development server,
> using Paramiko IIRC)

cvs.zope.org / svn.zope.org (same machine) run a stock sshd:  they use
the "command=" prefix on users' pubkeys to limit what that key can be
used to do (only SVN / CVS operations for any non-admin users).


Tres.
- --
===================================================================
Tres Seaver          +1 540-429-0999          tseaver at palladion.com
Palladion Software   "Excellence by Design"    http://palladion.com
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iEYEARECAAYFAks0SdcACgkQ+gerLs4ltQ795gCg2FDY353KLgJTXGgqz0CHQ1rE
2/UAoI7kUnEGxF2omBqh58JKSsFKEGVr
=yRkp
-----END PGP SIGNATURE-----



More information about the Distutils-SIG mailing list