Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

RFE: differentiate between known and trusted keys #3358

Open
pmatilai opened this issue Oct 4, 2024 · 0 comments
Open

RFE: differentiate between known and trusted keys #3358

pmatilai opened this issue Oct 4, 2024 · 0 comments
Labels
crypto Signatures, keys, hashes and their verification RFE

Comments

@pmatilai
Copy link
Member

pmatilai commented Oct 4, 2024

Currently, rpmkeys --import implies trusting that key: besides making it usable for signature checking, we allow installations of packages signed by that key (assuming enforcing mode as will be going forward)

It'd be useful, necessary even to differentiate between the two: If we consider a drop-in directory of pubkeys, any package can place a file in there, but trusting a package enough to install it does not mean we trust the package enough to write a open checks on our behalf.

@pmatilai pmatilai added RFE crypto Signatures, keys, hashes and their verification labels Oct 4, 2024
@dmnks dmnks added this to RPM Oct 22, 2024
@github-project-automation github-project-automation bot moved this to Backlog in RPM Oct 22, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
crypto Signatures, keys, hashes and their verification RFE
Projects
Status: Backlog
Development

No branches or pull requests

1 participant