Re: RPM signature verification

Marcus Meissner <[email protected]> Thu, 6 Oct 2016 08:53:35 +0200
Newsgroups gmane.linux.suse.security
Organization SUSE Linux GmbH, GF: Felix Imendörffer, Jane Smithard, Graham Norton, HRB 212 84 (AG Nürnberg)
Message-ID <[email protected]>
On Wed, Oct 05, 2016 at 11:03:28PM +0200, Malte Gell wrote:
> Hi there,
> 
> does RPM need to run gpg to verify signatures or is this hardcoded
> directly into RPM?

rpm has GPG signature verification built-in.
 
> What is the default behaviour of rpm if signature verification fails for
> whatever reason, does rpm abort installation of the package?

Depends.

By default libzypp (and so zypper/yast2) check the YUM repository for signatures and
follows the SHA256 checksums for the content including the RPMs.

The RPMs checksum is not checked.

New libzypp versions can however check RPM signatures instead of repository
signatures.

Ciao, Marcus
-- 
To unsubscribe, e-mail: [email protected]
To contact the owner, e-mail: [email protected]