Re: detached gpg signature on repomd.xml
Christoph Thiel <[email protected]>
| Newsgroups | gmane.linux.rpm.metadata |
|---|---|
| Message-ID | <[email protected]> |
On Sat, 26 Aug 2006, seth vidal wrote: > as a result of a rather lengthy and ranging discussion elsewhere it came > out that a gpg signature of repomd.xml would heighten the security of > using these type of repositories. That's exactly what we have been doing with our repos for SUSE Linux Enterprise 10 and openSUSE ;) Check out: http://en.opensuse.org/Secure_Installation_Sources#The_.22repomd.22_or_.22YUM.22_format Regards Christoph