http://lkiw4tmbudbr43hbyhm636sarn73vuow77czzohdbqdpjuq3vdzvenyd.onion/article/shawn-webb/2015-12-31/introducing-hardenedbsds-new-binary-updater
Validation steps: Extract main tarball Validate public cert against trusted root store If public cert does not belong to any root cert in the trust store, gracefully fail with an error message Validate each file that causes changes to the system has a corresponding .sig file If signature doesn't match, gracefully fail with an error message Continue on with update application Goal 3 - Scalability This goal is relatively easy to achieve.