Bug 219502
| Summary: | Ask the user if they want to import the gpg key, rather than just doing it | ||
|---|---|---|---|
| Product: | Red Hat Satellite 5 | Reporter: | James Bowes <jbowes> |
| Component: | Installer | Assignee: | Mike McCune <mmccune> |
| Status: | CLOSED WONTFIX | QA Contact: | Corey Welton <cwelton> |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | 500 | CC: | bkearney, rhn-bugs |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2007-04-04 18:26:34 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | |||
| Bug Blocks: | 173427 | ||
The satellite installer just blindly rpm --imports what it assumes will be the Red Hat gpg key. Someone could get sneaky and replace it with something else, compromising the system. Instead, we should ask the user if it's ok, saying where the gpg key is, and what the key id is, etc. Our wonderful Co-op says: <@kganong> jbowes, bretm-laptop: Its located in install_main.pl, sub setup_gpg <@kganong> jbowes: also located in satInstall.py, def addGPGKey, but I don't know if that is active code.