Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Adds sdw-config 0.5.5 rpm #19

Merged
merged 1 commit into from
Jun 9, 2021
Merged

Adds sdw-config 0.5.5 rpm #19

merged 1 commit into from
Jun 9, 2021

Conversation

conorsch
Copy link
Contributor

@conorsch conorsch commented Jun 9, 2021

Name of package: securedrop-workstation-dom0-config

Includes changes from:

Signed with the old/current key, i.e.
22245C81E3BAEB4138B36061310F561200F4AD77

Test plan

@sssoleileraaa
Copy link
Contributor

sssoleileraaa commented Jun 9, 2021

@conorsch the checksum i see on debian is:

6b17cb715398dcb4df1f33e508efaa177bc5182d14d6c7c7da9037de6caa0561  securedrop-workstation-dom0-config-0.5.5-1.fc25.noarch.rpm

on fedora:

6f2f262561149e2aa0ca0a10d102e58f4fb099fb41c0d7f6b63992f983d07813  securedrop-workstation-dom0-config-0.5.5-1.fc25.noarch.rpm

does this look correct?

@conorsch
Copy link
Contributor Author

conorsch commented Jun 9, 2021

That's not what I'd expect, let me check locally.

@sssoleileraaa
Copy link
Contributor

yeah, looks like it should be 3685dd6e80f518ac83f2645af798c9cccc51407324907120effaba7038908dba according to the logs

@conorsch
Copy link
Contributor Author

conorsch commented Jun 9, 2021

Looks like the repetitious addsign/delsign operations I did prior to uploading means we can't get back the initial checksum. (I tried, and failed, to dual-sign the rpm for the purposes of key rotation. That's not actually supported by rpm yet.) I've still got the original 3685dd6e80f518ac83f2645af798c9cccc51407324907120effaba7038908dba artifact locally, so I'll resign that just once and upload here.

Will do the same for freedomofpress/securedrop-yum-test#27

Includes changes from:

  * freedomofpress/securedrop-workstation#707
  * freedomofpress/securedrop-workstation#708

Signed with the old/current key, i.e.
22245C81E3BAEB4138B36061310F561200F4AD77
@conorsch
Copy link
Contributor Author

conorsch commented Jun 9, 2021

Try again, @creviera . Here's what I'm seeing locally:

  • signed version c81399f7a05f4f7b5955843774e2e6e61b0df051a835043c70cbb461eab69c32
  • after --delsign on Debian 3685dd6e80f518ac83f2645af798c9cccc51407324907120effaba7038908dba

The second matches what's in the build logs, as I'd expect.

Copy link
Contributor

@sssoleileraaa sssoleileraaa left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
No open projects
Development

Successfully merging this pull request may close these issues.

None yet

2 participants