[LU-1354] PGP Sign RPM's Created: 30/Apr/12 Updated: 01/Sep/21 |
|
| Status: | Open |
| Project: | Lustre |
| Component/s: | None |
| Affects Version/s: | Lustre 2.7.0, Lustre 2.5.5 |
| Fix Version/s: | None |
| Type: | New Feature | Priority: | Minor |
| Reporter: | Michael Di Domenico | Assignee: | Oleg Drokin |
| Resolution: | Unresolved | Votes: | 1 |
| Labels: | mq115 | ||
| Issue Links: |
|
||||
| Rank (Obsolete): | 10537 | ||||
| Description |
|
The current RHEL RPM's as delievered by whamcould are not signed with a PKI certificate. It would be beneficial if Whamcloud could sign the RPM's with PKI to verify that Whamcloud is in fact the author of the RPM's. |
| Comments |
| Comment by Brian Murrell (Inactive) [ 30/Apr/12 ] |
|
We certainly could create a GPG key and sign our RPMs with it. It would be a key with likely no web of trust to it from you though so how much would you really trust it? |
| Comment by Michael Di Domenico [ 01/May/12 ] |
|
Well some trust is better then no trust, eh? But it does provide someone an ability to verify that the packages were created by a specific person and that the packages have not been altered down the chain. as long as the passphrase is safe and the whamcloud servers remain protected, I should be able to sign-off to an auditor that the software I downloaded did in fact come from and was produced by Whamcloud. The only other way I can make that claim with any real distinction would be to have a (silver, non-r/w) CD mailed from whamcloud to me. |
| Comment by Andreas Dilger [ 06/Nov/13 ] |
|
There are several people (myself, Brian Murrell, maybe Oleg) on the HPDD team that have well-known keys that could sign an RPM-signing key. |
| Comment by Marcin Dulak [ 05/Mar/15 ] |
|
It would be valuable to have the RPMS finally signed - also in order to use them properly with configuration management tools like Puppet, etc. |
| Comment by Nathaniel Clark [ 29/Jan/19 ] |
|
If we're going to sign rpms, we should also consider signing the modules so they will work in a FIPS enabled kernel. https://www.kernel.org/doc/html/v4.15/admin-guide/module-signing.html
|
| Comment by Gerrit Updater [ 29/Jan/19 ] |
|
Nathaniel Clark (nclark@whamcloud.com) uploaded a new patch: https://review.whamcloud.com/34132 |
| Comment by Nathaniel Clark [ 30/Jan/19 ] |
|
After further investigation. The module signing / cert management is as follows:
NOTE: |
| Comment by Aurelien Degremont (Inactive) [ 12/Jul/19 ] |
|
Is there any news on this topic ? |
| Comment by James McKenna [ 25/Nov/19 ] |
|
Bumping this topic. Any news? |
| Comment by James A Simmons [ 31/Aug/21 ] |
|
Sigh. The latest Ubuntu enforces this now [ 4874.368433] Lockdown: insmod: unsigned module loading is restricted; see man kernel_lockdown.7 |
| Comment by Aurelien Degremont (Inactive) [ 01/Sep/21 ] |
|
By latest, do you mean latest kernel for Ubuntu 20.04 LTS, or kernel on latest Ubuntu 21.04 ? |