[Rpm-maint] Porting RPM to Sequoia PGP
Michael Schroeder
mls at suse.de
Fri Oct 29 07:15:55 UTC 2021
On Thu, Oct 28, 2021 at 05:17:33PM +0200, Justus Winter wrote:
> In my opinion, these signatures should be rejected by RPM. If working
> with nineties material is really a thing, the user should explicitly
> opt-into these unsafe algorithms.
Right. The way we usually do it in rpm is to make it configurable.
I.e. we would add a "%_allowed_signature_hashes" or
"%_forbidden_signature_hashes" so that we the admins can tweak
it to their needs.
Cheers,
Michael.
--
Michael Schroeder SUSE Software Solutions Germany GmbH
mls at suse.de GF: Felix Imendoerffer HRB 36809, AG Nuernberg
main(_){while(_=~getchar())putchar(~_-1/(~(_|32)/13*2-11)*13);}
More information about the Rpm-maint
mailing list