LWN.net Logo

The proposed Fedora key-migration plan

The proposed Fedora key-migration plan

Posted Aug 29, 2008 16:46 UTC (Fri) by pizza (subscriber, #46)
In reply to: The proposed Fedora key-migration plan by jamesh
Parent article: The proposed Fedora key-migration plan

If I recall correctly, the signatures are only used to verify the actual packages (ie RPMs) prior to installation. Once installed, the package signatures serve no further use as the packages are discarded.

Verification of the files installed by various packages takes place against RPM's local database of all installed files -- but that can't tell you if the original package was trustworthy or not.


(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds