Bug 144982 - RPM-GPG-KEYs for third party RPMs
Summary: RPM-GPG-KEYs for third party RPMs
Alias: None
Product: Fedora
Classification: Fedora
Component: fedora-release (Show other bugs)
(Show other bugs)
Version: 2
Hardware: All Linux
Target Milestone: ---
Assignee: Elliot Lee
QA Contact:
Keywords: FutureFeature
Depends On:
TreeView+ depends on / blocked
Reported: 2005-01-13 13:10 UTC by Kasper Dupont
Modified: 2007-11-30 22:10 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: Enhancement
Doc Text:
Story Points: ---
Clone Of:
Last Closed: 2005-01-19 23:26:54 UTC
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---

Attachments (Terms of Use)

Description Kasper Dupont 2005-01-13 13:10:08 UTC
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.3)

Description of problem:
The /usr/share/doc/fedora-release-2 directory contains only six public
keys. It would be nice if the public keys of well known providers of
RPM packages for Fedora Core were included as well (for example fedora
legacy, fresh rpms and others). Probably they should be in a seperate
directory along with an explanation that you provide no guarantee
whatsoever about the quality of rpm packages from these sources.
Having the public keys installed by Fedora Core means users don't have
to download them from an unauthenticated channel.

Version-Release number of selected component (if applicable):

How reproducible:

Steps to Reproduce:
1. ls /usr/share/doc/fedora-release-2

Additional info:

Comment 1 Elliot Lee 2005-01-19 23:26:54 UTC
The way you suggested doing it isn't that bad of an idea. However, it
seems better to let each repo distribute its own keys (to deal with
keys expiring, and give them more control to add packages signed with
new keys). As for authentication, typically, downloading keys is not a
big security problem - if it does become one, I'm sure someone will
think of a better solution than including the keys in the OS.

There's also the concern that including the keys of would be
sanctioning the repos, many of which include packages of questionable
legality or bad fit with Fedora Core's licensing goals.

Note You need to log in before you can comment on or make changes to this bug.