Hmm... I've been thinking of starting to using
Module::Signature on stand alone network, since verifying that the file was written as the author had intendeed is a good thing (tm). (In this case, a network that does not have access to the regular internet.) I would still like to have the ability to verify that the module was written as intended, but since the module makes queries to (a specific key server), how would one implement this? I have a couple of ideas, but I'm not sure which would be best or most feasible...
Update: Autrijus, the author of the module, replied below. He has a good plan and is working with people that run CPAN to address this concern.
- One could bring up a keyserver on a local network, which is publicly available, but I would have to somehow import the keys on to that server
- One could have a 'master file', simliar to the /CPAN/modules/01mailrc.txt.gz cpan file, which would contain a listing of all keys for all cpan signatures from a specific period in time for all module authors, which could be read in manually by the signare module to verify the signature...
- One could simply not worry (but this isn't the best option imho)
Any ideas? If people are interested, I might be able to write some code to support this...
Have a great one.
----
Zak