On 01/16/2009 Jesse Keating wrote: > Given that we can't revoke, yes, we plan to use new keys each release. > We can use gpg web-o-trust thing and sign the new keys with the old > keys > and whatnot, does that actually help people? Why couldn't we revoke keys? Even if RPM itself doesn't have the capability, we could have yum periodically check for updates on installed keys on keyservers through a plugin, I would imagine. -Doug
Attachment:
signature.asc
Description: OpenPGP digital signature
-- fedora-devel-list mailing list fedora-devel-list@xxxxxxxxxx https://www.redhat.com/mailman/listinfo/fedora-devel-list