Re: detached gpg signature on repomd.xml

Florian La Roche <[email protected]>
Newsgroups gmane.linux.rpm.metadata
Message-ID <[email protected]>
On Sat, Aug 26, 2006 at 12:30:18PM -0400, seth vidal wrote:
> Hi folks,
>  as a result of a rather lengthy and ranging discussion elsewhere it
> came out that a gpg signature of repomd.xml would heighten the security
> of using these type of repositories.

Ack, that would be useful. From repomd.xml we get sha1 for the other
repository data and primary.xml contains sha1 for all rpm packages.

regards,

Florian La Roche
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.