﻿id	summary	reporter	owner	description	type	status	priority	milestone	component	resolution	keywords	cc
48	xen: get rid of the downloadable *unsigned* components	joanna	joanna	"Xen Makefile downloads and builds some unsigned code, that we don't even use in Qubes (qemu, etc). Those files are downloaded over plaintext connection, so subject to easy subversion by an attacker in the middle. Such an attack might result in a compromised package or developers machine.

It's silly to have a signed xen package, that uses unsigned packages..."	defect	closed	major	Release 1 Beta 2	xen	fixed		
