[docs] Add signature check to install instructions #71
Labels
No labels
bugfix
cleanup
discussion
documentation
doing
done
feature
improvement
packaging
Stale
testing
TODO
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
ungleich-public/cdist#71
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The instructions should mention how to check signatures on install and update.
mentioned in commit
d5ac9ea348closed via commit
d5ac9ea348I think we just need to document installing cdist from source tarball + signature.
@nico IIRC, keypair is already put into ungleich keystore.
@poljakowski I think for the we'd need to generate our own keypair, put it likely into
passand then sign the resulting tar.xx. Generally speaking, a good idea.@evilham This signature is only valid if source tarball from tag release notes is used, or if tarball is created from the tag exactly the same as in release process.
Installing from this source tarball is not even documented :)
@evilham You mean on installing cdist and verifying https://code.ungleich.ch/ungleich-public/cdist/uploads/dec9becf9b372ec1c48cb022ae8936aa/cdist-6.2.0.tar.gz.asc, right?