[ILUG] Rpm signing.

Chris Collins chris.collins at ulaa.ul.ie
Wed Feb 6 12:28:33 GMT 2008


Afternoon ILUGers.

I've been googling around for information on digitally signing an rpm
file I'm creating.  It seems that rpm only supports signing with
gpg/pgp keys.

The problem I have is that the company has an x509 cert which it would
like to sign with.  Can anybody provide me with some insight into how
I can sign the rpm with the x509 cert?

For example, would it be possible to establish a chain of trust where
I create a pgp key at build time, sign the key with the cert, and sign
the rpm with the key?  Or is this too convoluted?

Thanks for any help.

-Chris
-- 
Chris Collins
m: +353 87 4189477
e: chris.collins at ulaa.ul.ie
http://www.linkedin.com/pub/3/41a/200



More information about the ILUG mailing list