This item is not in the Gentoo user FAQ. If you're even modestly paranoid about security, it's important that packages you download off the net be signed with digital signatures. MD5 only verifies that the packages have not been accidentally corrupted during transmission. A peek at the portage Python sources in webcvs reveals that it checks md5sums but doesn't appear to have any facility for digital signatures. So, does Gentoo's package system verify that packages are digitally signed before building them?
it only uses md5sums atm
Should this be added to the FAQ? //ZhEN
This is not really an enhancement. I am closing it. //ZhEN