-
Notifications
You must be signed in to change notification settings - Fork 279
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Feature Request: Allow pubkey validation with pkg bootstrap #1309
Comments
On 22/08/2015 19:27, Shawn Webb wrote:
The pkg that checks signatures during bootstrap is pkg(7) which is part It is probably going to be more productive for you to investigate
|
I guess the question stems down to: should |
The former, given pubkey is for now our only "simple mechanism" for signing. I have been willing to add it to pkg(7) for a while, but never found time |
Yeah. It really would've been nice to have it supported. I'm having to rework how we in HardenedBSD build packages. It seems that Poudriere doesn't support building package repos that use the fingerprint signature type. I end up having to re-run the |
Bugzilla ticket opened in FreeBSD: https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=202622 |
pkg bootstrap
currently doesn't supportsignature_type="pubkey"
. It either needs to or the pubkey signature type should be removed entirely in favor of fingerprints. This is a problem with downstream distributions like HardenedBSD who usesignature_type="pubkey"
and haven't yet made the switch to fingerprints due to lack of documentation surrounding fingerprints.The text was updated successfully, but these errors were encountered: