Bug 219502

Summary: Ask the user if they want to import the gpg key, rather than just doing it
Product: Red Hat Satellite 5 Reporter: James Bowes <jbowes>
Component: InstallerAssignee: Mike McCune <mmccune>
Status: CLOSED WONTFIX QA Contact: Corey Welton <cwelton>
Severity: medium Docs Contact:
Priority: medium    
Version: 500CC: bkearney, rhn-bugs
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2007-04-04 18:26:34 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On:    
Bug Blocks: 173427    

Description James Bowes 2006-12-13 16:21:13 UTC
The satellite installer just blindly rpm --imports what it assumes will be the
Red Hat gpg key. Someone could get sneaky and replace it with something else,
compromising the system. Instead, we should ask the user if it's ok, saying
where the gpg key is, and what the key id is, etc.

Our wonderful Co-op says:
 <@kganong> jbowes, bretm-laptop: Its located in install_main.pl, sub 
                 setup_gpg
 <@kganong> jbowes: also located in satInstall.py, def addGPGKey,   but I 
                 don't know if that is active code.