ceph / ceph/merfi

RFE: verify rpm-sign's --keyfile matches the signatures

Open
#48 1 comment 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
Python
Stars
3
Forks
3
PR merge metrics
No merged PRs in 30d

Description

`merfi rpm-sign` can optionally take a public key file (`--keyfile`). When this arg is present, merfi will copy the public key file as `release.asc` into the root of every discovered Debian repo.

There is nothing that sanity checks that this GPG public key matches the signatures that `rpm-sign`
generated. An operator could accidentally pick the wrong GPG pubkey that does not match `--key`. Currently the QE team is our only hope for catching this.

Ideally merfi should be able to automatically validate each signature against the `--keyfile` and ensure that the public key does in fact match the private key that generated the signatures.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.