Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.
Sign upFedora template upgrade docs should give advice about importing signing keys #2463
Comments
andrewdavidwong
added
C: doc
enhancement
labels
Nov 27, 2016
andrewdavidwong
added this to the
Documentation/website milestone
Nov 27, 2016
andrewdavidwong
closed this
in
QubesOS/qubes-doc@72dae15
Nov 27, 2016
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
andrewclausen commentedNov 27, 2016
Qubes OS version:
R3.2
Affected TemplateVMs:
fedora-23
Summary:
When upgrading the Fedora template from 23 to 24, dnf requires the user to approve importing a new key. This key was already checked when it was installed. The documentation ought to say that it is safe to import the key.
Details:
When following the Fedora 23 template upgrade instructions, the user gets asked to approve importing a key:
This leaves the user in a difficult position: should the user accept the key? Should the user verify it? It turns out that the key was installed by a package,
so a signature for the key was already checked. Therefore, it is safe to say "yes" without doing any more checks.
Proposed Solution:
I think the documentation (linked above) should add a step (after step 5) saying: "
dnfmight ask you to approve importing a new package signing key. This key was already checked when it was installed, so you can safely say yes."