[Rpm-maint] [rpm-software-management/rpm] rpmsign: enable signing files with PKCS11 tokens (PR #4125)
Panu Matilainen
notifications at github.com
Tue Mar 24 07:27:48 UTC 2026
pmatilai left a comment (rpm-software-management/rpm#4125)
> Hey folks, just a gentle nudge here. Are there any changes or additional tests people want before this is acceptable?
Heh, I've been wondering about more or less the same - is there something more coming?
The patch as such looks fine and acceptable to me. What's missing is updating the rpmsign man page to cover this functionality. As for the `--fskpath="pkcs11:token=...` stuff, I haven't got the faintest idea, so relying on @simo5 and @neverpanic for an "ack" on that part.
I did just spot this comment from the above though:
> Typically I would say we should create a separate OpenSSL library context when loading new providers, but since this is a simple one-shot tool, I don't think that's a concern here.
rpmsign itself is a simple one-shot tool, but technically this bit is in the librpmsign library, which could be used in some other kind of context too, such as a daemon.
--
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/pull/4125#issuecomment-4115994573
You are receiving this because you are subscribed to this thread.
Message ID: <rpm-software-management/rpm/pull/4125/c4115994573 at github.com>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.rpm.org/pipermail/rpm-maint/attachments/20260324/2cad2f69/attachment.htm>
More information about the Rpm-maint
mailing list