[Rpm-maint] [rpm-software-management/rpm] RFE: support payloadless signing in rpmsign (Issue #3991)

Daniel Alley notifications at github.com
Fri Apr 17 19:23:35 UTC 2026


dralley left a comment (rpm-software-management/rpm#3991)

> means to slice the head (lead+signature+header) out of an rpm for the purposes of sending back and forth for signing, basically https://github.com/rpm-software-management/rpm/issues/3843
> 
> means to append the payload of the original rpm to the signed one, verifying the result

Strictly speaking, it could be enough to just extract the header portion for signing since the lead is irrelevant and the signature header could be manipulated locally rather than remotely.  Unless the idea is to receive the entire metadata portion of the package from the signing service, instead of just the signatures.

In the former case, maybe that would allow for updating the package in-place if there's sufficient space in the reserved portion of the signature header


-- 
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/issues/3991#issuecomment-4270692494
You are receiving this because you are subscribed to this thread.

Message ID: <rpm-software-management/rpm/issues/3991/4270692494 at github.com>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.rpm.org/pipermail/rpm-maint/attachments/20260417/43c85ead/attachment.htm>


More information about the Rpm-maint mailing list