|
|
|
|
|
by sophacles
1217 days ago
|
|
Let's encrypt solved this by doing a proof of control over the domain name, and in an automated way. Pypi could do this. Or, they could require that someone demonstrate proof of ownership for a namespace by signing it with a certificate tied to the domain name (so you couldn't claim the com.bigco namespace without having the certs, which you can't get without owning that domain). There could even be signature requirements/proof for each package and/or version uploaded. |
|