[Rpm-maint] [rpm-software-management/rpm] rpmsign: enable signing files with PKCS11 tokens (PR #4125)
Panu Matilainen
notifications at github.com
Thu Mar 12 07:10:12 UTC 2026
@pmatilai commented on this pull request.
> +[[slots]]
+slot = 1
+dbtype = "sqlite"
+dbargs = "${token_dir}/token.sql"
+KRYOPTIC_EOF
+pkcs11-tool --module "${pkcs11_mod}" --init-token \
+ --label "${token_label}" --so-pin "${token_pin}"
+pkcs11-tool --module "${pkcs11_mod}" --init-pin \
+ --login --so-pin "${token_pin}" --pin "${token_pin}"
+pkcs11-tool --module "${pkcs11_mod}" --login \
+ --pin "${token_pin}" --keypairgen --key-type EC:prime256v1 \
+ --id 01 --label "ima-signing"
+
+RPMTEST_CHECK([[
+cp /data/RPMS/hello-2.0-1.x86_64.rpm /tmp/
+rpmsign --addsign --key-id 4344591E1964C5FC --signfiles \
Messing with other projects dlopen()'s is not something we want to get into, unless there's a clean way to do so. Also, not worth rebuilding something just for the sake of one test. So lets just conditionalize on ENABLE_ASAN for now. It's far from ideal, but then this isn't exactly functionality that runs on each and every rpm execution either.
--
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/pull/4125#discussion_r2922717752
You are receiving this because you are subscribed to this thread.
Message ID: <rpm-software-management/rpm/pull/4125/review/3934428280 at github.com>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.rpm.org/pipermail/rpm-maint/attachments/20260312/3c2a9424/attachment-0001.htm>
More information about the Rpm-maint
mailing list