Signed RPM Packages

Lasse Karstensen lkarsten at varnish-software.com
Wed May 28 09:44:51 CEST 2014


[ A bit late to the party, sorry. ]

On Fri, May 16, 2014 at 07:55:30PM +0200, Per Buer wrote:
> On Fri, May 16, 2014 at 6:16 PM, Jason Woods <devel at jasonwoods.me.uk> wrote:
[..]
> > But noticed that the GPG signature checking of the RPMs was not enabled,
> > and the RPMs were transferred over plaintext HTTP!
[..]
> Lasse might have more information wrt to the state of the packages right
> now. I know he has been working on the RPMs quite a bit lately.

The plan is to start signing RPMs with the upcoming 4.0.1 release.

We won't introduce this in 3.0 this late in its lifetime. Please use HTTPS when installing them.

-- 
Lasse Karstensen
with Varnish release manager hat



More information about the varnish-misc mailing list