[Bug 998] Network install/upgrade is unsafe, should check GPG signatures.

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



https://bugzilla.redhat.com/show_bug.cgi?id=998



--- Comment #51 from Peter Lawler <redhat-bugzilla@xxxxxxxxxxxxx> ---
Just had a 'crazy' 'early morning' though about this. I'm not an anaconda
expert by any means, but figured I'd throw this out there and see if it floats,
is already floating or sinking.

It's not uncommon for remote machines to keep LUKS keys on a USB stick plugged
in to a machine. I'm wondering if it's not possible to also read the needed
bits for the GPG/Certs for the install phase off the key as well.

As I say, don't know if this is already doable, let alone how. I'm imagining
some kernel flag/s at install time.

It wouldn't fix all cases, such as those machines which can't take a USB stick
(either by policy or physical design), but it'd be something at least.

Anyway, as I say, I realise it's a completely clueless question/suggestion that
I'm more than happy to be shot down in flames over :)

-- 
You are receiving this mail because:
You are on the CC list for the bug.
Unsubscribe from this bug https://bugzilla.redhat.com/token.cgi?t=HcEAiVGIfV&a=cc_unsubscribe
--
relnotes-content mailing list
relnotes-content@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/relnotes-content





[Index of Archives]     [Fedora Users]     [Fedora Desktop]     [Fedora SELinux]     [Big List of Linux Books]     [Yosemite News]     [Gnome Users]     [KDE Users]

  Powered by Linux