signatures for non-rpm files in $arch/os trees?

Todd Zullinger tmz at pobox.com
Sun Mar 25 17:45:41 UTC 2007


Hi all,

Is there some way to verify the integrity of the non-rpm files
included in the $arch/os tree?  I'm thinking of the images/
specifically.

If I want to kick off an install I could download the rescue disk iso,
check the gpg sig on the SHA1SUM file, and then verify the sha1sum for
the rescue image.  But if I just want to grab boot.iso or diskboot.img
and do the same thing, I don't know of a way to verify those images.

Is there some way to do this or is there good reason that doing so is
pointless?

-- 
Todd        OpenPGP -> KeyID: 0xBEAF0CE3 | URL: www.pobox.com/~tmz/pgp
======================================================================
Marriages are made in heaven. But so are thunder, lightning, and hail.

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 542 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/fedora-devel-list/attachments/20070325/33711ebf/attachment.sig>


More information about the fedora-devel-list mailing list