[Rpm-maint] [rpm-software-management/rpm] Document rpmkeys output and the overall verify policy in some detail (PR #4170)
Michal Domonkos
notifications at github.com
Thu Apr 2 16:15:11 UTC 2026
@dmnks commented on this pull request.
> @@ -79,19 +80,102 @@ See *rpm-common*(8) for the options common to all *rpm* executables.
configured keystore backend.
This can be used to convert from one key storage to another.
+# VERIFICATION POLICY
+To deal with three generations of package formats and as many decades of
+cryptographic algorithms and differing system policies, the RPM package
+verification is a complicated system with many moving parts.
+
+RPM packages contain multiple individual _verifiables_ that cover different
+parts of the package: header, payload or both, using different cryptographic
+algorithms. There are two _classes_ of verifiables: digests and signatures,
+and a class-level pass/fail result is calculated independently for each,
Although I can see how that would increase the repetition of "class" in the sentence... so not sure 😆
--
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/pull/4170?email_source=notifications&email_token=ADLPZUYNLTL4VKABGI36IDD4T2GY7A5CNFSNUABKM5UWIORPF5TWS5BNNB2WEL2QOVWGYUTFOF2WK43UKJSXM2LFO4XTIMBVGE3TENRSG422M4TFMFZW63VKON2WE43DOJUWEZLEUVSXMZLOOS6XA4S7OJSXM2LFO5PW433UNFTGSY3BORUW63TTL5RWY2LDNM#discussion_r3029010862
You are receiving this because you are subscribed to this thread.
Message ID: <rpm-software-management/rpm/pull/4170/review/4051726275 at github.com>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.rpm.org/pipermail/rpm-maint/attachments/20260402/95e665a8/attachment-0001.htm>
More information about the Rpm-maint
mailing list