Posted Sep 11, 2008 16:34 UTC (Thu) by jake (editor, #205)
[Link]
> If you run yum with the -y it will import the key automatically.
Fine, but that still doesn't verify that the key it is trying to import is the key you are wanting to import. In order to verify that (i.e. check the key signature), the manual step is required.
Since package signing keys were part of whatever the "infrastructure issues" were, it would seem prudent to verify them before importing them.
jake
Fedora distributes new keys
Posted Sep 11, 2008 16:39 UTC (Thu) by skvidal (subscriber, #3094)
[Link]
Agreed. It is a great idea. I suggest verifying keys to everyone. I just wanted to be clear that it wasn't REQUIRED in any code sense.