Bug 11048

Summary: Missing documentation about generation of rpm signed packages.
Product: [Documentation] Mega Manual Reporter: Jose Perez C <jose.perez.carranza>
Component: mega-manualAssignee: Scott Rifenbark <srifenbark>
Status: RESOLVED FIXED QA Contact:
Severity: normal    
Priority: Medium CC: bluelightning, mark.hatle, markus.lehtonen, randy.macleod, srifenbark
Version: 2.3   
Target Milestone: 2.3 M4   
Hardware: x86   
OS: Multiple   
Whiteboard: 10 April 2017: RESOLVED
OS type for building Yocto: --- Type of Regression: ---
Verified: Documentation change: Done (doc changes complete)

Description Jose Perez C 2017-02-10 22:01:23 UTC
Currently mega manual has no information or reference about how to build rpm packages with signature, would be good if a reference or example is added to the manual.
Comment 1 Scott Rifenbark 2017-02-14 01:42:59 UTC
Hi, 

Accepting and looking into this.  Adding Paul Eggleton to CC list.  Set days to 2.0 and target to 2.3M4.

Scott
Comment 2 Stephen K Jolley 2017-02-16 15:43:01 UTC
Markus,  Can you answer Scott's question?
Comment 3 Markus Lehtonen 2017-02-17 08:10:35 UTC
Sorry, what was the question, again?
Comment 4 Scott Rifenbark 2017-02-20 16:42:02 UTC
Hi, 

I am not sure who would provide this information to me but I need information on how to build rpm packages with signature.  I don't know how to do this.  Once I have the information, I can get it into the manual in the appropriate spot(s).  This is the reason I copied Paul Eggleton on the bug.  So, you might not be the right person Markus... Stephen takes these bugs in the NEEDINFO state and assigns them to someone that should be able to provide the information.  

Thanks,
Scott
Comment 5 Markus Lehtonen 2017-02-21 16:00:14 UTC
Sorry, I was just confused as I didn't see any question. And sure, I'm probably the correct person to answer the question.
    
In order to enable rpm signing the user needs to have the following specified in the bitbake config (i.e. local.conf or distro config etc):
# Inherit sign_rpm.bbclass to enable signing functionality
INHERIT += " sign_rpm"
# Define the GPG key that will be used for signing.
RPM_GPG_NAME = "<key_name>"
# Provide passhphrase for the key
RPM_GPG_PASSPHRASE = "<passphrase>"

There are two optional variables related to signing:
GPG_BIN - this variable can be used to specify a specific gpg binary/wrapper which will be executed when signing

GPG_PATH - this variable can be used to specify the gpg home directory to be used



In addition to rpm package signing, also the package feeds (i.e. repositories) may be signed. Package feed signing is currently supported for rpm and ipk backends, but, not for dpkg backend.

Enabling package feed signing is rather similar to enabling package signing. The user needs to define the following in the config:
INHERIT += "sign_package_feed"
PACKAGE_FEED_GPG_NAME = "<key_name>"
PACKAGE_FEED_GPG_PASSPHRASE_FILE = "<path_to_file_containing_passphrase>"

The difference is that for package feed signing the passphrase is not put in the config, but, must reside in a separate file. From a technical standpoint this is more secure as the passhprase is not in plaintext in the configuration.

Package feed signing has three optional variables:
GPG_BIN - common with rpm signing, specifies the gpg binary to execute

GPG_PATH - common with rpm signing, specifies gpg home directory

PACKAGE_FEED_GPG_SIGNATURE_TYPE - specifies the type of gpg signature. Only available for the ipk backend, it is ignored for other backends. Allowed values: 
   ASC    ascii armored, this is the default
   BIN    binary



I hope I was able to explain it in somehow comprehensible manner. Please let me know if you need more clarification on this.
Comment 6 Markus Lehtonen 2017-02-22 12:05:11 UTC
Assigning back to Scott. Please let me know if you need more details
Comment 7 Scott Rifenbark 2017-02-28 17:56:01 UTC
Markus, 

Great information.  I will take this and work with it.  I will update the bug when there is something to review for you. 

Setting to IN PROGRESS DESIGN.

Scott
Comment 8 Scott Rifenbark 2017-03-16 18:27:13 UTC
Hi Marcus, 

I have a new section in the dev-manual that discusses this signed package and feed stuff.  See http://www.yoctoproject.org/docs/2.3/dev-manual/dev-manual.html#generating-and-using-signed-packages.  In addition to this documentation, I will need to create some new variable entries in the glossary for the supporting variables.  That will come later.  I would like you to take a look at this new section for now so we can settle on the technical accurracy and such before I do the variable stuff.  There will undoubtably also be some referencing from other areas of the YP docs that will need to be put in as well.  I will get to that also when this section is settled.  

Can you take a look for me and comment?  One thing I am a bit confused on is the support.  It seems that we can only sign RPM packages and we can only use package feeds from RPM or IPK -- not DPKG.  Is that correct?

Thanks,
Scott
Comment 9 Scott Rifenbark 2017-03-27 21:35:34 UTC
Set Target to 2.3 M4.  I had the wrong release in there (2.4).

Also, I think I might understand this a bit better now.  My understanding is that we can only sign RPM packages as described in http://www.yoctoproject.org/docs/2.3/dev-manual/dev-manual.html#signing-rpm-packages.  And then the following section about "Processing Package Feeds" (http://www.yoctoproject.org/docs/2.3/dev-manual/dev-manual.html#processing-package-feeds) has to do with just feeds with IPK packages. 

Is this right?

Let me know.

Scott
Comment 10 Scott Rifenbark 2017-04-10 18:21:26 UTC
This doc bug is good.  Marking as RESOLVED and putting the doc flag to "done."

Scott