Re: rpm --checksig not using gnupg trustdb

From: Bart Martens (bart.martens@advalvas.be)
Date: 03/08/02


From: bart.martens@advalvas.be (Bart Martens)
Date: Thu, 07 Mar 2002 23:25:48 GMT

In article <3c87f783$0$35571$2c3e98f8@news.voyager.net>, lynx wrote:
> "Bart Martens" <bart.martens@advalvas.be>, in
><slrna8bivc.1tk.bart.martens@cable-195-162-215-141.upc.chello.be>:
>
> [use a separate directory to hold gpg keys for RPM's use]
>
>> However, that is a workaround, not normal use of GnuPG with rpm. You
>> lose the feature of also automatically trusting keys trustworthy keys
>> via the trustdb- mechanism.
>
> i may be daft - what, exactly, would prevent you from creating and/or
> using a trustdb in /etc/rpm-keys ?

Nothing. But it would be useless because rpm doesn't use it. See my first
post in this thread.

>> You also lose the feature of automatically
>> importing keys from a keyserver.
>
> that's a bug, not a feature. you don't *want* to do that.

No. That's a feature, not a bug. See options --no-auto-key-retrieve
and --keyserver in the man page.



Relevant Pages

  • [Full-Disclosure] RPM verification
    ... Axel Grossklaus wrote: ... | | Product: rpm ... | --keyring only _adds_ keys in the keyring. ... that it would "embed" gpg or so into rpm. ...
    (Full-Disclosure)
  • Re: rpm --checksig not using gnupg trustdb
    ... > You need to set up RPM to see the correct path for your gpg keys. ... the trust path between your personal keys and the keys of the rpm packagers ...
    (comp.os.linux.security)
  • Re: Yum gpg keys -
    ... as I run into the problem with livna, dries, etc. ... You can find the keys on the ISO image, or on any of the mirror ... You install them using rpm --import as root. ... correct path to the key file. ...
    (Fedora)
  • Re: RPM instalations question
    ... You need GnuPG to verify this message ... if someone tries to use the script attached to make rpm ... happy with the new keys. ... packages or once you build/recompiled on your own, ...
    (alt.os.linux)
  • [Full-Disclosure] RPM verification
    ... | Product: rpm ... on the suse distribution the keys for rpm validation are already kept in ... --keyring only _adds_ keys in the keyring. ... unfortunately, this is not really easy to do system-wide, since gpg ...
    (Full-Disclosure)

Quantcast