Unsigned rpm's

Thomas Springer th.springer at gmx.net
Fri Feb 24 13:21:13 UTC 2006


Rainer Koenig
> > up2date has a --nosig parameter which turns of signature checks.

Rudolf Kastl:
> id not recommend to turn of sig checking.


Though I want also recommand gpg sig checking,..

... I've written a yum-plugin which adds an option to overwrite yums
default setting defined in yum.conf

# yum --gpgcheck=[0|1] localinstall package [packages]

If someone want to tryout and even use it get it here:

http://www.cs.uni-frankfurt.de/~springer/yum-plugin/

Please mail me off-list in case of questions/problems/...

I will probably add some information/recommandation soon, like it's
always better to install needed keys then turn off sig checking and only
disable gpgcheck when you build a package on your own.


Thomas
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 191 bytes
Desc: This is a digitally signed message part
URL: <http://listman.redhat.com/archives/fedora-list/attachments/20060224/6bb915cc/attachment-0001.sig>


More information about the fedora-list mailing list