A couple of thoughts:

  - In non-interactive environments, the secret key material should probably 
not be made available to the build infrastructure.  That means exactly 
something like gpg-agent (a daemon that provides a smartcard like interface) is 
needed.
  - How does rpm figure out what key to use for signing?
 


-- 
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/issues/2678#issuecomment-1738753306
You are receiving this because you are subscribed to this thread.

Message ID: <rpm-software-management/rpm/issues/2678/1738753...@github.com>
_______________________________________________
Rpm-maint mailing list
Rpm-maint@lists.rpm.org
http://lists.rpm.org/mailman/listinfo/rpm-maint

Reply via email to