]> code.ossystems Code Review - openembedded-core.git/commit
rpm: disable external key server
authoryzhu1 <yanjun.zhu@windriver.com>
Wed, 8 Jul 2015 03:30:57 +0000 (11:30 +0800)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Wed, 8 Jul 2015 12:14:06 +0000 (13:14 +0100)
commitfdaa9115fb20d4af49ce8407b5785096c66ecf6c
tree42bd1ec6e7b0ac8b6ba9319948bc1da8df06a50a
parentc82557d2bf8c3d8081754561df46cba530103164
rpm: disable external key server

When RPM experiences a signed package, with a signature that it does NOT know.
By default it will send the -fingerprint- (and only the 16 digit fingerprint)
to an external HKP server, trying to get the key down.

This is probably not a reasonable default behavior for the system to do,
instead it should simply fail the key lookup.  If someone wants to enable the
HKP server it's easy enough to do by enabling the necessary macros.

Signed-off-by: yzhu1 <yanjun.zhu@windriver.com>
Signed-off-by: Roy Li <rongqing.li@windriver.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-devtools/rpm/rpm/rpm-macros.in-disable-external-key-server.patch [new file with mode: 0644]
meta/recipes-devtools/rpm/rpm_5.4.14.bb