Should we use gpg signatures also for our ISO images? #188
Labels
No labels
Done
bug
buildiso
buildpkg
buildtree
critical
deployiso
duplicate
enhancement
help wanted
in progress
invalid
manjaro-chroot
note
old-not-relevant
optional
question
sonar
todo
wontfix
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
tools/manjaro-tools#188
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Created by: philmmanjaro
Hi team,
should we use also gpg signatures for our ISO images? Seems some are more sensitive now ...
I think that's a great idea. Works really simple once you have your gpg keys set up...
https://www.gnupg.org/gph/en/manual/x135.html
Created by: udeved
We should add a counterpart to signpkg, signiso.
Created by: udeved
Awesome! 😎 Thank you!!
Created by: philmmanjaro
We should communicate how to setup the gpg-keyring for manjaro-tools.
Created by: udeved
Yes, it uses makepkg.conf provided key however.
A guide how to configure ssh and gpg agent.
Created by: philmmanjaro
I assume by default disabled and therefore optional until properly set up ...
Created by: udeved
Yes, only on -s arg.
resonance to the first signed ISO is quite positive :) Some more suggestions here fyi https://forum.manjaro.org/index.php?topic=31426.msg258941#msg258941