A couple of thoughts:
- In non-interactive environments, the secret key material should probably
not be made available to the build infrastructure. That means exactly
something like gpg-agent (a daemon that provides a smartcard like interface) is
needed.
- How does rpm figure out what key to use for signing?
--
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/issues/2678#issuecomment-1738753306
You are receiving this because you are subscribed to this thread.
Message ID: <rpm-software-management/rpm/issues/2678/1738753...@github.com>
_______________________________________________
Rpm-maint mailing list
Rpm-maint@lists.rpm.org
http://lists.rpm.org/mailman/listinfo/rpm-maint