Bug 15504 - Releases are not signed with a well-known key
Summary: Releases are not signed with a well-known key
Status: RESOLVED FIXED
Alias: None
Product: Release Process
Classification: Infrastructure
Component: Release Process (show other bugs)
Version: unspecified
Hardware: All Multiple
: Medium+ major
Target Milestone: 5.1 M2
Assignee: Michael Halstead
QA Contact:
URL:
Whiteboard:
Depends on:
Blocks:
 
Reported: 2024-06-05 21:50 UTC by contact
Modified: 2024-06-20 16:46 UTC (History)
2 users (show)

See Also:
OS type for building Yocto: ---
Type of Regression: ---
Verified:
Documentation change: Don't know


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description contact 2024-06-05 21:50:56 UTC
When downloading Yocto or any of its components there is no way to verify it is the official release of the software. If the server was compromised it would be extremely easy to release malicious source code or binaries as there's no way to verify them at the moment. The Git tree and releases are GPG signed, but the key has no method of verification.

Having instructions on verifying release hashes and Git tags using GPG as well as advertising the key fingerprint out of band and explaining who does the signing and where would solve this issue.

The current key "Yocto Build and Release <releases@yoctoproject.org>" seems like it may be automated and signed during CI. Having a developer manually sign the Git tree would be a much better solution for building trust as it involves some form of oversight.
Comment 1 Michael Halstead 2024-06-07 22:38:44 UTC
I've started to document at
https://wiki.yoctoproject.org/wiki/GPG_sign_notes_%26_git_tags.

Please add wiki sections you'd like to see filled in and ask any questions on the discussion page https://wiki.yoctoproject.org/wiki/index.php?title=Talk:GPG_sign_notes_%26_git_tags&action=edit.
Comment 2 contact 2024-06-07 23:52:52 UTC
Thank you for the start. I don't have an account on the wiki so I can't contribute further on this issue.
Comment 3 Richard Purdie 2024-06-10 11:55:48 UTC
If there are specific questions you'd like to see answered you could also add them here if you can't get access to the wiki
Comment 4 Michael Halstead 2024-06-20 16:46:37 UTC
I'm going to mark this resolved for now. Please go ahead and request a wiki account if you'd like to participate there. You may also reopen this bug with additional comments if you prefer.