Re: signing

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 




On Apr 23, 2012 2:51 PM, "Christopher Howard" <christopher.howard@xxxxxxxxxxxxxx> wrote:
>
> I build my RPMs on one system but GPG sign them on another, which seems
> to work fine with the rpmsign command. I was just wondering: is it
> customary to sign just the source RPM, or both the source and binary
> RPMs? Does it hurt anything to sign both?

I sign both srpm and rpm as myself (the packager).

they get re-signed with the deployment key when it's copied to the yum server.

hth,
-paul

--
packaging mailing list
packaging@xxxxxxxxxxxxxxxxxxxxxxx
https://admin.fedoraproject.org/mailman/listinfo/packaging

[Index of Archives]     [Fedora Users]     [Fedora Desktop]     [Fedora SELinux]     [Big List of Linux Books]     [Yosemite Forum]     [KDE Users]

  Powered by Linux