Toying around with the test cases I wonder if the opposite is actually what we 
want. If there are only keys that do not actually match you'd want to issue a 
NOKEY response. But for that we'd need to actually understand which key is the 
matching one - if any.

We do get an meaningful error message from the back end if signature and pubkey 
don't match up though.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/issues/3334#issuecomment-2428916917
You are receiving this because you are subscribed to this thread.

Message ID: <rpm-software-management/rpm/issues/3334/[email protected]>
_______________________________________________
Rpm-maint mailing list
[email protected]
http://lists.rpm.org/mailman/listinfo/rpm-maint

Reply via email to