Fix signing key path to avoid conflating auth and signing identities
- Change default from ~/.ssh/id_rsa to ~/.ssh/id_xbps - Add comment explaining key separation - Update script documentation to match Addresses code review finding: default signing key should not be the user's personal SSH authentication key. Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
This commit is contained in:
co-authored by
CommandCodeBot
parent
985efed906
commit
37a0ed7030
@@ -263,8 +263,8 @@ package: package-deb package-rpm
|
|||||||
|
|
||||||
# ─── XBPS packaging (ADR 0008) ─────────────────────────────────────────────
|
# ─── XBPS packaging (ADR 0008) ─────────────────────────────────────────────
|
||||||
|
|
||||||
XBPS_SIGNING_KEY ?= $(HOME)/.ssh/id_rsa
|
# XBPS signing key (separate from SSH authentication key)
|
||||||
XBPS_SIGNED_BY ?= Fenris Packaging <packaging@bongbetic.com>
|
XBPS_SIGNING_KEY ?= $(HOME)/.ssh/id_xbps
|
||||||
|
|
||||||
package-xbps: stage
|
package-xbps: stage
|
||||||
@echo "=== Building XBPS package ==="
|
@echo "=== Building XBPS package ==="
|
||||||
|
|||||||
@@ -10,7 +10,7 @@ set -euo pipefail
|
|||||||
#
|
#
|
||||||
# Environment:
|
# Environment:
|
||||||
# XBPS_SIGNING_KEY - Path to SSH RSA private key for XBPS signing
|
# XBPS_SIGNING_KEY - Path to SSH RSA private key for XBPS signing
|
||||||
# (default: ~/.ssh/id_rsa)
|
# (default: ~/.ssh/id_xbps)
|
||||||
# SIGNED_BY - Signature identity string
|
# SIGNED_BY - Signature identity string
|
||||||
# (default: "Fenris Packaging <packaging@bongbetic.com>")
|
# (default: "Fenris Packaging <packaging@bongbetic.com>")
|
||||||
#
|
#
|
||||||
@@ -25,7 +25,7 @@ GITEA_OWNER="xavierk"
|
|||||||
GITEA_REPO="Fenris-xbps"
|
GITEA_REPO="Fenris-xbps"
|
||||||
GITEA_BRANCH="stable"
|
GITEA_BRANCH="stable"
|
||||||
ARCH="x86_64"
|
ARCH="x86_64"
|
||||||
XBPS_SIGNING_KEY="${XBPS_SIGNING_KEY:-$HOME/.ssh/id_rsa}"
|
XBPS_SIGNING_KEY="${XBPS_SIGNING_KEY:-$HOME/.ssh/id_xbps}"
|
||||||
SIGNED_BY="${SIGNED_BY:-Fenris Packaging <packaging@bongbetic.com>}"
|
SIGNED_BY="${SIGNED_BY:-Fenris Packaging <packaging@bongbetic.com>}"
|
||||||
|
|
||||||
# ── Parse arguments ──────────────────────────────────────────────────────
|
# ── Parse arguments ──────────────────────────────────────────────────────
|
||||||
|
|||||||
Reference in New Issue
Block a user