Skip to content

[FR?] InRelease Signed-By field support #1497

@LebedevRI

Description

@LebedevRI

https://wiki.debian.org/DebianRepository/Format#Signed-By says:

Signed-By
An optional field containing a comma separated list of OpenPGP key fingerprints to be used for validating the next Release file. The fingerprints must consist only of hex digits and may not contain spaces. The fingerprint specifies either the key the Release file must be signed with or the key the signature key must be a subkey of. The later match can be disabled by appending an exclamation mark to the fingerprint.

If the field is present, a client should only accept future updates to the repository that are signed with keys listed in the field. The field should be ignored if the Valid-Until field is not present or if it is expired.

Unless i'm really missing it, aptly does not produce this field,
and can not be configured to produce this field. Is that correct?

It would be nice if the value for that field could be configured,
with MVP being treating it as a opaque textual field without actual validation,
that can be configured during aptly publish (snapshot|repo).

Thank you!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions