Signing and consumer repo setup: rpm payload signing, key publication, pinned docs #51
Notifications
Due Date
No due date set.
Blocks
Depends on
Reference: xavierk/Fenris#51
Reference in New Issue
Block a user
Parent
Ship Fenris as native deb + rpm packages (execute the release plan)
What to build
Trust for the channel: the rpm payload is signed at build time with the dedicated packaging key and verifiable end-to-end by dnf through a Fenris-owned repo file; the checksum manifest is clearsigned; the public key is published in-repo; and consumer setup docs pin the exact fingerprints — with the key ceremony (import, sign, delete) documented for the maintainer.
Acceptance criteria
Blocked by
Resolved — all acceptance criteria verified:
make sign-rpm(rpmsign with dedicated packaging key); verification passes; fenris.repo with gpgkey enables dnf installmake clearsign; verification documented in READMEChanges: Makefile (signing targets, release flow), docs/install/signing-key-ceremony.md (key lifecycle), packaging/keys/fenris-packaging.asc (raw URL, ceremony ref), README.md (consumer install, verification, migration), docs/spec/release-packaging.md (ceremony doc, rpmsign), tests/test_signing.py (36 structural tests).
Test results: 36/36 signing tests pass, 337/337 non-packaging tests pass.