Re: detached gpg signature on repomd.xml
seth vidal <[email protected]>
| Newsgroups | gmane.linux.rpm.metadata |
|---|---|
| Message-ID | <1156829072.29242.10.camel@cutter> |
On Mon, 2006-08-28 at 15:12 +0200, Christoph Thiel wrote: > On Mon, 28 Aug 2006, seth vidal wrote: > > > > > I actually meant on the verification end, not on the signing side. > > > > > > > > sorry, I realized that wasn't clear. > > > > > > Well, we have the code in libzypp -- but that's C++. > > > > ah, okay - I didn't know if you had added it to a yum pkg for suse or in > > a plugin. > > Not, it's a YaST-only thingy so far. But agreeing on a common solution > would be very much appreciated! ;) > I'm relatively comfy with what you've described for signing the repomd.xml. Checking it is up to the discretion of the tool accessing it, I'd guess. -sv