[tor-bugs] #12871 [RPM packaging]: RPM repo data is not signed and documentation misses repo_gpgcheck

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Sep 22 10:30:11 UTC 2014


#12871: RPM repo data is not signed and documentation misses repo_gpgcheck
-------------------------------+----------------------
     Reporter:  cypherpunks    |      Owner:  hiviah
         Type:  defect         |     Status:  assigned
     Priority:  normal         |  Milestone:
    Component:  RPM packaging  |    Version:
   Resolution:                 |   Keywords:
Actual Points:                 |  Parent ID:
       Points:                 |
-------------------------------+----------------------

Comment (by hiviah):

 Repomd.xml files will be signed from now on
 (https://gitweb.torproject.org/user/hiviah/rpm-build-scripts.git) and
 current instance on servers is signed as well.

 BTW I think that mirrorlists in various distros were over https, but most
 of the repomd.xml links and also direct download links were plain http.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/12871#comment:4>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list