[
https://issues.apache.org/jira/browse/CASSANDRA-14968?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16737654#comment-16737654
]
Michael Shuler commented on CASSANDRA-14968:
--------------------------------------------
The apache organization there has a key - I don't know if it would be feasible
to use the org key to sign the repositories? Individual users can upload public
(and private (eww..)) keys and the API for bintray includes notes about signing
via curl POST calls. I personally would not upload my private key anywhere,
regardless of what ASF's opinion on that might be. Uploading a public key so
the repo makes it available for download is pretty normal, then the signing
portion (I guess) can be done offline(?) and uploaded.
I don't know all the ins and outs of how it works. This is precisely why this
ticket suggests investigating the topic. Is this something you would like
assigned to you?
> Investigate GPG signing of deb and rpm repositories via bintray
> ---------------------------------------------------------------
>
> Key: CASSANDRA-14968
> URL: https://issues.apache.org/jira/browse/CASSANDRA-14968
> Project: Cassandra
> Issue Type: Bug
> Reporter: Michael Shuler
> Priority: Major
> Labels: packaging
>
> Currently, the release manager uploads debian packages and built/signed
> metadata to a generic bintray repository. Perhaps we could utilize the GPG
> signing feature of the repository, post-upload, via the bintray GPG signing
> feature.
> https://www.jfrog.com/confluence/display/BT/Managing+Uploaded+Content#ManagingUploadedContent-GPGSigning
> Depends on CASSANDRA-14967
--
This message was sent by Atlassian JIRA
(v7.6.3#76005)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]