Detached signatures are problematic for mirrored content because it's very 
difficult to guarantee that those files are synced together. It's also 
difficult to guarantee consumers will _have_ signatures to validate. That's the 
reason why Debian tooling generally doesn't support signed packages and nothing 
really generates or validates debsigs. I'd rather continue to have a contiguous 
blob with signatures in the RPM header like we do now.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/issues/1482#issuecomment-757560040
_______________________________________________
Rpm-maint mailing list
Rpm-maint@lists.rpm.org
http://lists.rpm.org/mailman/listinfo/rpm-maint

Reply via email to