Hasty reply, sorry if I miss a point. [And in my hast I forgot to CC
the list, sigh. Here's another copy.]
On 2022-05-18 17:19, Zomb Hacker wrote:
Depends on what you mean by ‘trusted’, but yes.
For substitutes:
~~~~~~~~~~~~~~~~
- There's an independent but trusted build farm at
"https://bordeaux.guix.gnu.org". You can add this to your list of
substitute URLs, *and* authorise its signing key[0], to make Guix poll
it for substitutes instead of [or in addition to] ci.guix.gnu.org.
- There's also a Chinese mirror of ci.guix.gnu.org at
just serves whatever ci.guix.gnu.org does.
This means that even though it's not run by the project, its
substitutes will be signed with the ‘official’ ci.guix.gnu.org key,
which your Guix trusts out of the box. You don't need to authorise
another key, and the SJTUG admins cannot modify & sign malicious
binaries.
They can of course *see* what you download. If you're worried about
that, use Tor as explained by Ludovic.
For Guix ISOs
~~~~~~~~~~~~~
…the situation is less straightforward:
- ftp.gnu.org, which can be reached from Russia, hosts only releases,
and Guix 1.3 is over a year old by this point. It's supported, but…
- I recommend you download the equivalent to
a while.
I also can't tell you how to easily add alternative substitute servers
in the Guix installer itself, as I've never done so myself. Sorry.
Kind regards,
T G-R
[0]: