[Rpm-maint] [rpm-software-management/rpm] RPMv6 proposal: Detached signatures (#1482)

Neal Gompa (ニール・ゴンパ) notifications at github.com
Sun Jan 10 23:05:18 UTC 2021


Detached signatures are problematic for mirrored content because it's very difficult to guarantee that those files are synced together. It's also difficult to guarantee consumers will _have_ signatures to validate. That's the reason why Debian tooling generally doesn't support signed packages and nothing really generates or validates debsigs. I'd rather continue to have a contiguous blob with signatures in the RPM header like we do now.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/issues/1482#issuecomment-757560040
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.rpm.org/pipermail/rpm-maint/attachments/20210110/4b5753b2/attachment.html>


More information about the Rpm-maint mailing list