OBS signd and GnuPG with Thales HSM
26 Jul
2022
26 Jul
'22
17:58
I have GnuPG with Thales HSM installed on a system to be my dedicated signing server. I can "rpm -addsign PACKAGE.rpm" and it is signed as expected. I believe that I need to copy the OBS /usr/sbin/signd and /etc/systemd/system/multi-user.target.wants/obssignd.service to this system. I'm not sure how to configure obssignd.service or /etc/signd.conf to simply use my enhanced rpm without it trying to do its own private key management/configuration. Am I on the right track?
26 Jul
26 Jul
19:22
I suspect that I need to use "--project" for calling /usr/sbin/signd from obssignd.service
879
Age (days ago)
879
Last active (days ago)
1 comments
1 participants
participants (1)
-
George Kraft