Signing metadata requires a lot of manual interaction and knowledge of the customer. This was the reason why we never implemented it for SUMA as the benefit was very low.

Now with the change in the zypp stack to not allow installing unsigned RPMs without user interaction or completly disabling GPG checks the benefit of such a feature increased.

I plan to implement this without any GUI support.

  • the customer need to create an own GPG key pair
  • the customer need to enable this feature in the config and configure the keyid and the password
  • during metadata generation the taskomatic task check, if metadata signing is configured and only then sign them
  • if metadata signing is configured, we need to change the GPG check options of the repos.

Looking for hackers with the skills:

susemanager uyuni

This project is part of:

Hack Week 17

Activity

  • almost 2 years ago: dmaiocchi liked Teach SUMA to sign repository metadata
  • almost 2 years ago: mcalmer added keyword "susemanager" to Teach SUMA to sign repository metadata
  • almost 2 years ago: mcalmer added keyword "uyuni" to Teach SUMA to sign repository metadata
  • almost 2 years ago: mcalmer started Teach SUMA to sign repository metadata
  • almost 2 years ago: mcalmer originated Teach SUMA to sign repository metadata

  • Comments

    Be the first to comment!

    Similar Projects

    Uyuni: re-architecting code with Akka by moio

    Simplify the codebase by using a more _modern...


    SUSE Manager: Better feedback for scheduled actions by fkobzik

    Motivation

    Running async actions in SUSE ...


    Testing GNU/Linux distributions on Uyuni by juliogonzalezgil

    Join the rocket chat channel! [https://chat.su...


    Investigate options to introduce Plugins to SUSE Manager by cbosdonnat

    For years we have been discussing the idea to m...


    Testing GNU/Linux distributions on Uyuni by juliogonzalezgil

    Join the rocket chat channel! [https://chat.su...


    Uyuni: re-architecting code with Akka by moio

    Simplify the codebase by using a more _modern...


    Provisioning Prometheus exporters with Uyuni revisited by j_renner

    There is a number of annoyances and pending imp...


    Investigate options to introduce Plugins to SUSE Manager by cbosdonnat

    For years we have been discussing the idea to m...