Making PGP distribution key well-known

Petr Pisar ppisar at redhat.com
Thu Mar 1 16:52:40 UTC 2012


As new Fedora release looms ahead, I'd like open discussion about
verifying distribution integrity. In short---where to get public key for
verifying RPM signatures.

If I remember correctly, you are asked to accept new signing key by rpm
while installing fedora-release package from new Fedora release. Problem
is, there is no way how how to verify the key beeing accepted.

I have been told by RPM developers, RPM allows multiple signatures.
Whould it be possible to sign fedora-relase package from F17 with key
used in F16 in addition?

This procedure would create chain of trust from older to newer Fedora
release making upgrade more secured.

Of course other good approach is to sign F17 public key by well-known
Fedora developers and publish the key with its singatures, e.g. on PGP
key servers.

-- Petr



More information about the devel mailing list