Currently mega manual has no information or reference about how to build rpm packages with signature, would be good if a reference or example is added to the manual.
Hi, Accepting and looking into this. Adding Paul Eggleton to CC list. Set days to 2.0 and target to 2.3M4. Scott
Markus, Can you answer Scott's question?
Sorry, what was the question, again?
Hi, I am not sure who would provide this information to me but I need information on how to build rpm packages with signature. I don't know how to do this. Once I have the information, I can get it into the manual in the appropriate spot(s). This is the reason I copied Paul Eggleton on the bug. So, you might not be the right person Markus... Stephen takes these bugs in the NEEDINFO state and assigns them to someone that should be able to provide the information. Thanks, Scott
Sorry, I was just confused as I didn't see any question. And sure, I'm probably the correct person to answer the question. In order to enable rpm signing the user needs to have the following specified in the bitbake config (i.e. local.conf or distro config etc): # Inherit sign_rpm.bbclass to enable signing functionality INHERIT += " sign_rpm" # Define the GPG key that will be used for signing. RPM_GPG_NAME = "<key_name>" # Provide passhphrase for the key RPM_GPG_PASSPHRASE = "<passphrase>" There are two optional variables related to signing: GPG_BIN - this variable can be used to specify a specific gpg binary/wrapper which will be executed when signing GPG_PATH - this variable can be used to specify the gpg home directory to be used In addition to rpm package signing, also the package feeds (i.e. repositories) may be signed. Package feed signing is currently supported for rpm and ipk backends, but, not for dpkg backend. Enabling package feed signing is rather similar to enabling package signing. The user needs to define the following in the config: INHERIT += "sign_package_feed" PACKAGE_FEED_GPG_NAME = "<key_name>" PACKAGE_FEED_GPG_PASSPHRASE_FILE = "<path_to_file_containing_passphrase>" The difference is that for package feed signing the passphrase is not put in the config, but, must reside in a separate file. From a technical standpoint this is more secure as the passhprase is not in plaintext in the configuration. Package feed signing has three optional variables: GPG_BIN - common with rpm signing, specifies the gpg binary to execute GPG_PATH - common with rpm signing, specifies gpg home directory PACKAGE_FEED_GPG_SIGNATURE_TYPE - specifies the type of gpg signature. Only available for the ipk backend, it is ignored for other backends. Allowed values: ASC ascii armored, this is the default BIN binary I hope I was able to explain it in somehow comprehensible manner. Please let me know if you need more clarification on this.
Assigning back to Scott. Please let me know if you need more details
Markus, Great information. I will take this and work with it. I will update the bug when there is something to review for you. Setting to IN PROGRESS DESIGN. Scott
Hi Marcus, I have a new section in the dev-manual that discusses this signed package and feed stuff. See http://www.yoctoproject.org/docs/2.3/dev-manual/dev-manual.html#generating-and-using-signed-packages. In addition to this documentation, I will need to create some new variable entries in the glossary for the supporting variables. That will come later. I would like you to take a look at this new section for now so we can settle on the technical accurracy and such before I do the variable stuff. There will undoubtably also be some referencing from other areas of the YP docs that will need to be put in as well. I will get to that also when this section is settled. Can you take a look for me and comment? One thing I am a bit confused on is the support. It seems that we can only sign RPM packages and we can only use package feeds from RPM or IPK -- not DPKG. Is that correct? Thanks, Scott
Set Target to 2.3 M4. I had the wrong release in there (2.4). Also, I think I might understand this a bit better now. My understanding is that we can only sign RPM packages as described in http://www.yoctoproject.org/docs/2.3/dev-manual/dev-manual.html#signing-rpm-packages. And then the following section about "Processing Package Feeds" (http://www.yoctoproject.org/docs/2.3/dev-manual/dev-manual.html#processing-package-feeds) has to do with just feeds with IPK packages. Is this right? Let me know. Scott
This doc bug is good. Marking as RESOLVED and putting the doc flag to "done." Scott