[Rpm-maint] [rpm-software-management/rpm] rpmsign: enable signing files with PKCS11 tokens (PR #4125)

Simo Sorce notifications at github.com
Fri Feb 27 13:45:27 UTC 2026


simo5 left a comment (rpm-software-management/rpm#4125)

Resolving a SPKI id to a private key is possible but require the certificate to be on the token with the same CKA_ID ... so needs to be tested carefully. If the token is something like a proper HSM we should be able to make it work, if it is something like a yubikey the certificate route may fail to work.

Generally I would recommend passing in a pkcs11 URI that identifies the key directly if possible, but if not possible we can try to deal with this in pkcs11-provider.



-- 
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/pull/4125#issuecomment-3973041693
You are receiving this because you are subscribed to this thread.

Message ID: <rpm-software-management/rpm/pull/4125/c3973041693 at github.com>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.rpm.org/pipermail/rpm-maint/attachments/20260227/f9ce29b0/attachment-0001.htm>


More information about the Rpm-maint mailing list