Hi folks, I want to add "intro to IMA signing" instructions to https://docs.pagure.org/koji/signing/ . I wrote a basic PR at https://pagure.io/koji/pull-request/3206 but it lacks technical details. - How do I generate my own new keypair so I can IMA-sign an RPM? - Can I use my existing GPG keypair? - How do I IMA-sign files in an RPM locally (apart from Koji)? (Is it the --signfiles option from rpmsign(8)?) - How do I inspect the IMA signatures on an existing RPM? - When I gpg-sign an RPM with "Key A" and IMA-sign an RPM with "Key B", does Koji "know" about Key B at all? - Ken _______________________________________________ devel mailing list -- devel@xxxxxxxxxxxxxxxxxxxxxxx To unsubscribe send an email to devel-leave@xxxxxxxxxxxxxxxxxxxxxxx Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/devel@xxxxxxxxxxxxxxxxxxxxxxx Do not reply to spam on the list, report it: https://pagure.io/fedora-infrastructure