Files
Fenris/packaging/keys/fenris-packaging.asc
T
xavierkandCommandCodeBot d8fa6df072 signing: rpm payload signing, key publication, consumer repo setup for #51
Implement the signing and consumer-repo trust infrastructure:

- Makefile: add generate-test-key, sign-rpm, checksums, clearsign targets;
  make release now automates the full build→sign→checksum→clearsign flow
- Key ceremony: document the import→sign→delete lifecycle, key rotation
  outline, and private-key-in-password-manager policy
- Public key: update placeholder with raw URL, algorithm, and ceremony ref
- Consumer docs: README now covers apt signed-by keyring flow, dnf repo
  file setup, signature verification commands, and migration runbook link
- Release spec: updated to reference ceremony doc and rpmsign workflow
- Tests: 36 structural signing tests (nfpm config, Makefile targets,
  repo file, key publication, ceremony doc, consumer docs, spec refs)
  plus throwaway-key RPM signature and clearsign mechanics; no network
  or real key required

Co-authored-by: CommandCodeBot <noreply@commandcode.ai>
2026-09-03 14:14:55 +05:30

19 lines
795 B
Plaintext

# Fenris Packaging Key — placeholder
#
# The public half of the dedicated RSA-3072 packaging key used to sign rpm
# payloads and clearsign SHA256SUMS manifests.
#
# The private half lives only in the password manager. Each release performs:
# import → sign → delete. No machine permanently holds signing material.
#
# Key details (published with the first Release):
# Algorithm: RSA 3072
# UID: Fenris Packaging <packaging@bongbetic.com>
# Expiry: 2 years from creation
#
# This file will be replaced with the real public key at the time of the
# first Release. Its raw URL doubles as the dnf gpgkey target:
# https://git.bongbetic.com/xavierk/Fenris/raw/branch/main/packaging/keys/fenris-packaging.asc
#
# See docs/install/signing-key-ceremony.md for the full key lifecycle.