[Rpm-maint] [rpm-software-management/rpm] rpmsign: enable signing files with PKCS11 tokens (PR #4125)
Jeremy Cline
notifications at github.com
Tue Mar 3 18:00:20 UTC 2026
@jeremycline commented on this pull request.
> +[[slots]]
+slot = 1
+dbtype = "sqlite"
+dbargs = "${token_dir}/token.sql"
+KRYOPTIC_EOF
+pkcs11-tool --module "${pkcs11_mod}" --init-token \
+ --label "${token_label}" --so-pin "${token_pin}"
+pkcs11-tool --module "${pkcs11_mod}" --init-pin \
+ --login --so-pin "${token_pin}" --pin "${token_pin}"
+pkcs11-tool --module "${pkcs11_mod}" --login \
+ --pin "${token_pin}" --keypairgen --key-type EC:prime256v1 \
+ --id 01 --label "ima-signing"
+
+RPMTEST_CHECK([[
+cp /data/RPMS/hello-2.0-1.x86_64.rpm /tmp/
+rpmsign --addsign --key-id 4344591E1964C5FC --signfiles \
Also, looking at the logs I see some "No slots" messages, but copy-pasting this into a `make shell` environment successfully sets up the token. The documentation makes me think that if it works in make shell it should also work in the test, but that doesn't seem to be true?
--
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/pull/4125#discussion_r2879739488
You are receiving this because you are subscribed to this thread.
Message ID: <rpm-software-management/rpm/pull/4125/review/3884236892 at github.com>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.rpm.org/pipermail/rpm-maint/attachments/20260303/5c8d8ce5/attachment-0001.htm>
More information about the Rpm-maint
mailing list