Re: [Rpm-maint] [rpm-software-management/rpm] Header signatures alone are not sufficient (#1672)

2021-10-21 Thread Demi Marie Obenour
@DemiMarie pushed 1 commit. 0bd36c11c2e5d9ec1a9f79a30db29ba909cf6e7e Header signatures alone are not sufficient -- You are receiving this because you are subscribed to this thread. View it on GitHub:

Re: [Rpm-maint] [rpm-software-management/rpm] Header signatures alone are not sufficient (#1672)

2021-07-05 Thread Demi Marie Obenour
@ffesti ping -- You are receiving this because you are subscribed to this thread. Reply to this email directly or view it on GitHub: https://github.com/rpm-software-management/rpm/pull/1672#issuecomment-874223443___ Rpm-maint mailing list

[Rpm-maint] [rpm-software-management/rpm] Header signatures alone are not sufficient (#1672)

2021-05-05 Thread Demi Marie Obenour
This fixes how RPM handles packages that contain a header signature, but neither header+payload signature nor payload digests. Such packages are obviously not properly signed, but RPM previously accepted them. This could be used to confuse both ‘rpmkeys -K’ and DNF. Both would report that the