<!-- 
RSS generated by JIRA (9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c) at Sat Feb 10 01:15:54 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>Whamcloud Community JIRA</title>
    <link>https://jira.whamcloud.com</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>9.4.14</version>
        <build-number>940014</build-number>
        <build-date>05-12-2023</build-date>
    </build-info>


<item>
            <title>[LU-1354] PGP Sign RPM&apos;s</title>
                <link>https://jira.whamcloud.com/browse/LU-1354</link>
                <project id="10000" key="LU">Lustre</project>
                    <description>&lt;p&gt;The current RHEL RPM&apos;s as delievered by whamcould are not signed with a PKI certificate.  It would be beneficial if Whamcloud could sign the RPM&apos;s with PKI to verify that Whamcloud is in fact the author of the RPM&apos;s.&lt;/p&gt;</description>
                <environment></environment>
        <key id="14206">LU-1354</key>
            <summary>PGP Sign RPM&apos;s</summary>
                <type id="2" iconUrl="https://jira.whamcloud.com/secure/viewavatar?size=xsmall&amp;avatarId=11311&amp;avatarType=issuetype">New Feature</type>
                                            <priority id="4" iconUrl="https://jira.whamcloud.com/images/icons/priorities/minor.svg">Minor</priority>
                        <status id="1" iconUrl="https://jira.whamcloud.com/images/icons/statuses/open.png" description="The issue is open and ready for the assignee to start work on it.">Open</status>
                    <statusCategory id="2" key="new" colorName="default"/>
                                    <resolution id="-1">Unresolved</resolution>
                                        <assignee username="green">Oleg Drokin</assignee>
                                    <reporter username="mdidomenico">Michael Di Domenico</reporter>
                        <labels>
                            <label>mq115</label>
                    </labels>
                <created>Mon, 30 Apr 2012 12:52:48 +0000</created>
                <updated>Wed, 1 Sep 2021 08:37:05 +0000</updated>
                                            <version>Lustre 2.7.0</version>
                    <version>Lustre 2.5.5</version>
                                                        <due></due>
                            <votes>1</votes>
                                    <watches>17</watches>
                                                                            <comments>
                            <comment id="35899" author="brian" created="Mon, 30 Apr 2012 14:55:21 +0000"  >&lt;p&gt;We certainly could create a GPG key and sign our RPMs with it.  It would be a key with likely no web of trust to it from you though so how much would you really trust it?&lt;/p&gt;</comment>
                            <comment id="35916" author="mdidomenico" created="Tue, 1 May 2012 11:45:57 +0000"  >&lt;p&gt;Well some trust is better then no trust, eh?  But it does provide someone an ability to verify that the packages were created by a specific person and that the packages have not been altered down the chain.&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;http://docs.redhat.com/docs/en-US/Red_Hat_Network_Satellite/5.3/html/Deployment_Guide/satops-rpm-building.html&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;http://docs.redhat.com/docs/en-US/Red_Hat_Network_Satellite/5.3/html/Deployment_Guide/satops-rpm-building.html&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;as long as the passphrase is safe and the whamcloud servers remain protected, I should be able to sign-off to an auditor that the software I downloaded did in fact come from and was produced by Whamcloud.  The only other way I can make that claim with any real distinction would be to have a (silver, non-r/w) CD mailed from whamcloud to me.&lt;/p&gt;</comment>
                            <comment id="70877" author="adilger" created="Wed, 6 Nov 2013 17:33:10 +0000"  >&lt;p&gt;There are several people (myself, Brian Murrell, maybe Oleg) on the HPDD team that have well-known keys that could sign an RPM-signing key.&lt;/p&gt;</comment>
                            <comment id="108894" author="marcindulak" created="Thu, 5 Mar 2015 15:32:43 +0000"  >&lt;p&gt;It would be valuable to have the RPMS finally signed - also in order to use them properly with configuration management tools like Puppet, etc.&lt;/p&gt;</comment>
                            <comment id="240878" author="utopiabound" created="Tue, 29 Jan 2019 16:12:32 +0000"  >&lt;p&gt;If we&apos;re going to sign rpms, we should also consider signing the modules so they will work in a FIPS enabled kernel.&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/security_guide/chap-federal_standards_and_regulations&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/security_guide/chap-federal_standards_and_regulations&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://www.kernel.org/doc/html/v4.15/admin-guide/module-signing.html&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://www.kernel.org/doc/html/v4.15/admin-guide/module-signing.html&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&#160;&lt;/p&gt;</comment>
                            <comment id="240888" author="gerrit" created="Tue, 29 Jan 2019 18:38:50 +0000"  >&lt;p&gt;Nathaniel Clark (nclark@whamcloud.com) uploaded a new patch: &lt;a href=&quot;https://review.whamcloud.com/34132&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://review.whamcloud.com/34132&lt;/a&gt;&lt;br/&gt;
Subject: &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-1354&quot; title=&quot;PGP Sign RPM&amp;#39;s&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-1354&quot;&gt;LU-1354&lt;/a&gt; build: Sign kernel modules during build&lt;br/&gt;
Project: fs/lustre-release&lt;br/&gt;
Branch: master&lt;br/&gt;
Current Patch Set: 1&lt;br/&gt;
Commit: a51e35b679049fbe1e358dd98b3158df0f5abd25&lt;/p&gt;</comment>
                            <comment id="240961" author="utopiabound" created="Wed, 30 Jan 2019 13:26:10 +0000"  >&lt;p&gt;After further investigation. The module signing / cert management is as follows:&lt;/p&gt;
&lt;ol&gt;
	&lt;li&gt;During the kernel build, a unique pub/priv key is generated (using info in &lt;tt&gt;kernelsource/x509.genkey&lt;/tt&gt;):
&lt;div class=&quot;preformatted panel&quot; style=&quot;border-width: 1px;&quot;&gt;&lt;div class=&quot;preformattedContent panelContent&quot;&gt;
&lt;pre&gt;kernelsource/signing_key.{x509,priv}
&lt;/pre&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ol&gt;


&lt;ol&gt;
	&lt;li&gt;All certificates in kernel source dir (files with the .x509 extension) are signed with the per-kernel key and included in the default trust chain.&lt;/li&gt;
	&lt;li&gt;All kernel modules are signed with the &lt;tt&gt;signing_key&lt;/tt&gt; and thus any module signed with those would also be acceptable.&lt;/li&gt;
&lt;/ol&gt;


&lt;p&gt;NOTE:&lt;br/&gt;
CentOS does not sign any of the provided kmod-* packaged modules.&lt;/p&gt;</comment>
                            <comment id="251261" author="degremoa" created="Fri, 12 Jul 2019 16:10:46 +0000"  >&lt;p&gt;Is there any news on this topic ?&lt;/p&gt;</comment>
                            <comment id="258783" author="jmckenna" created="Mon, 25 Nov 2019 17:19:35 +0000"  >&lt;p&gt;Bumping this topic.  Any news?&lt;/p&gt;</comment>
                            <comment id="311722" author="simmonsja" created="Tue, 31 Aug 2021 16:50:18 +0000"  >&lt;p&gt;Sigh. The latest Ubuntu enforces this now &lt;img class=&quot;emoticon&quot; src=&quot;https://jira.whamcloud.com/images/icons/emoticons/sad.png&quot; height=&quot;16&quot; width=&quot;16&quot; align=&quot;absmiddle&quot; alt=&quot;&quot; border=&quot;0&quot;/&gt;&lt;/p&gt;

&lt;p&gt;[ 4874.368433] Lockdown: insmod: unsigned module loading is restricted; see man kernel_lockdown.7&lt;/p&gt;</comment>
                            <comment id="311784" author="degremoa" created="Wed, 1 Sep 2021 08:37:05 +0000"  >&lt;p&gt;By latest, do you mean latest kernel for Ubuntu 20.04 LTS, or kernel on latest Ubuntu 21.04 ?&lt;/p&gt;</comment>
                    </comments>
                <issuelinks>
                            <issuelinktype id="10011">
                    <name>Related</name>
                                                                <inwardlinks description="is related to">
                                                        </inwardlinks>
                                    </issuelinktype>
                    </issuelinks>
                <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                                                                                                                <customfield id="customfield_10890" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_10390" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>1|hzw2t3:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10090" key="com.pyxis.greenhopper.jira:gh-global-rank">
                        <customfieldname>Rank (Obsolete)</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>10537</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                </customfields>
    </item>
</channel>
</rss>