-
Notifications
You must be signed in to change notification settings - Fork 1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Adds sdw-config 0.5.5 rpm #19
Conversation
@conorsch the checksum i see on debian is:
on fedora:
does this look correct? |
That's not what I'd expect, let me check locally. |
yeah, looks like it should be |
Looks like the repetitious addsign/delsign operations I did prior to uploading means we can't get back the initial checksum. (I tried, and failed, to dual-sign the rpm for the purposes of key rotation. That's not actually supported by rpm yet.) I've still got the original 3685dd6e80f518ac83f2645af798c9cccc51407324907120effaba7038908dba artifact locally, so I'll resign that just once and upload here. Will do the same for freedomofpress/securedrop-yum-test#27 |
Includes changes from: * freedomofpress/securedrop-workstation#707 * freedomofpress/securedrop-workstation#708 Signed with the old/current key, i.e. 22245C81E3BAEB4138B36061310F561200F4AD77
730167f
to
49d122d
Compare
Try again, @creviera . Here's what I'm seeing locally:
The second matches what's in the build logs, as I'd expect. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
- Tag in securedrop-workstation repository is correct: https://github.com/freedomofpress/securedrop-workstation/releases/tag/0.5.5
- Build logs are included: freedomofpress/build-logs@da7964d
- CI is passing, the rpm is properly signed with the prod key
- Unsigned RPM after running
rpm --delsign
on the signed RPM results in the checksum found in the build logs
> ran this on Debian with the latest change and it matches what's in the build logs now
Name of package:
securedrop-workstation-dom0-config
Includes changes from:
Signed with the old/current key, i.e.
22245C81E3BAEB4138B36061310F561200F4AD77
Test plan
rpm --delsign
on the signed RPM results in the checksum found in the build logs