Re: Doubt on the security model of OBS repo signing
[email protected] Thu, 14 Sep 2017 00:12:34 +0800
| Newsgroups | gmane.linux.suse.security |
|---|---|
| Message-ID | <[email protected]> |
On 2017-09-13 23:26, Marcus Meissner wrote: > Hi, > > Thank you for your long and detailed E-Mail! I'm really sorry for having written too much. Here's a short summary for other readers who don't want to read the previous mail: The GPG keys for OBS are delivered in plain HTTP and require manual check, which could be improved. > We have a while ago enabled https support on download.opensuse.org and > the next step is what you suggest in "Step 3" for us, namely changing > software.opensuse.org to deliver https instead of http URLs. > > (I had opened https://github.com/openSUSE/software-o-o/issues/123 a > while ago > and sent a pull request after receiving your e-mail.) > > The GPG chain of trust model is tricky for package management and we > have > been reviewing improvements on that on or off, there likely is work to > do. Thank you for your efforts on making openSUSE better! By the way, have you considered those 2 other suggestions? (embedding GPG into ymp file, displaying GPG key in OBS project page) Embedding the key also opens an opportunity for 3rd-party commercial software repo, so they don't need a separate "rpm --import". -- Best regards, StarBrilliant -- To unsubscribe, e-mail: [email protected] To contact the owner, e-mail: [email protected]