#5870: rawhide signing

Fedora Release Engineering rel-eng at fedoraproject.org
Thu May 22 17:30:13 UTC 2014


#5870: rawhide signing
------------------------------+-----------------------
  Reporter:  kevin            |      Owner:  rel-eng@…
      Type:  task             |     Status:  new
 Milestone:  Fedora 21 Final  |  Component:  koji
Resolution:                   |   Keywords:  meeting
Blocked By:                   |   Blocking:
------------------------------+-----------------------

Comment (by till):

 == Implementation idea ==

 Create a proxy services that caches credentials for sigul and uses sigul
 to sign rawhide RPMs.

 == Tasks ==
  * Create new VM to host the service
  * Setup VM to be able to run sigul
  * Allow till access to VM
  * Create sigul users for primary and secondary Rawhide keys
  * write service

 == Proxy Service Description ==
  * Requires credentials for primary/secondary Rawhide keys before it is
 ready for operation, therefore e.g. ask on startup
  * Store credentials in memory
  * Listen on fedmsg
  * Whenenver a new Rawhide package is built on primary or secondary sign
 the respective RPMs using cached credentials

-- 
Ticket URL: <https://fedorahosted.org/rel-eng/ticket/5870#comment:15>
Fedora Release Engineering <http://fedorahosted.org/rel-eng>
Release Engineering for the Fedora Project


More information about the rel-eng mailing list