Re: Doubt on the security model of OBS repo signing

[email protected] Thu, 14 Sep 2017 00:12:34 +0800
Newsgroups gmane.linux.suse.security
Message-ID <[email protected]>
On 2017-09-13 23:26, Marcus Meissner wrote:
> Hi,
> 
> Thank you for your long and detailed E-Mail!

I'm really sorry for having written too much.
Here's a short summary for other readers who don't want to read the 
previous mail:
The GPG keys for OBS are delivered in plain HTTP and require manual 
check, which could be improved.

> We have a while ago enabled https support on download.opensuse.org and
> the next step is what you suggest in "Step 3" for us, namely changing
> software.opensuse.org to deliver https instead of http URLs.
> 
> (I had opened https://github.com/openSUSE/software-o-o/issues/123 a 
> while ago
> and sent a pull request after receiving your e-mail.)
> 
> The GPG chain of trust model is tricky for package management and we 
> have
> been reviewing improvements on that on or off, there likely is work to 
> do.

Thank you for your efforts on making openSUSE better!

By the way, have you considered those 2 other suggestions? (embedding 
GPG into ymp file, displaying GPG key in OBS project page)
Embedding the key also opens an opportunity for 3rd-party commercial 
software repo, so they don't need a separate "rpm --import".

-- 
Best regards,
StarBrilliant
-- 
To unsubscribe, e-mail: [email protected]
To contact the owner, e-mail: [email protected]