[ 
https://issues.apache.org/jira/browse/CASSANDRA-14968?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16738342#comment-16738342
 ] 

Michael Shuler commented on CASSANDRA-14968:
--------------------------------------------

The apache bintray organization for people to research: 
https://bintray.com/apache

An example of an apache project using bintray for both rpm and deb repositories 
for people to research:
https://ignite.apache.org/download.cgi#rpm-package
https://ignite.apache.org/download.cgi#deb-package

The deb repo for ignite:
https://bintray.com/apache/ignite-deb/apache-ignite#files/dists%2Fapache-ignite

Checking gpg signature on deb repo and metadata that apt/apt-get/aptitude 
clients use to verify integrity of install files, after downloading those files 
from bintray manually:
{noformat}
mshuler@hana:~/tmp$ ls -l apache-ignite_*                              
-rw-r--r-- 1 mshuler mshuler 2154 Jan  9 09:30 apache-ignite_Packages
-rw-r--r-- 1 mshuler mshuler 2679 Jan  9 09:18 apache-ignite_Release
-rw-r--r-- 1 mshuler mshuler  821 Jan  9 09:15 apache-ignite_Release.gpg
mshuler@hana:~/tmp$ 
mshuler@hana:~/tmp$ gpg apache-ignite_Release.gpg
gpg: WARNING: no command supplied.  Trying to guess what you mean ...
Detached signature.
Please enter name of data file: apache-ignite_Release
gpg: Signature made Thu 06 Dec 2018 05:36:26 AM CST
gpg:                using RSA key 379CE192D401AB61
gpg: please do a --check-trustdb
gpg: Good signature from "Bintray (by JFrog) <[email protected]>" [unknown]
gpg: WARNING: This key is not certified with a trusted signature!
gpg:          There is no indication that the signature belongs to the owner.
Primary key fingerprint: 8756 C4F7 65C9 AC3C B6B8  5D62 379C E192 D401 AB61
mshuler@hana:~/tmp$ 
mshuler@hana:~/tmp$ cat apache-ignite_Release
Origin: Bintray
Label: Bintray
Suite: apache-ignite
Codename: apache-ignite
Date: Thu, 06 Dec 2018 11:36:25 UTC
Components: main
Architectures: amd64 i386
MD5Sum:
 d14dd7acdcef58e0e2948f808abb3a31             2154 main/binary-all/Packages
 c39c9e7aa83bbad644183f6debc02724              860 main/binary-all/Packages.bz2
 29ebf0da941a3982a75772b16cf83ddd              706 main/binary-all/Packages.gz
 d14dd7acdcef58e0e2948f808abb3a31             2154 main/binary-amd64/Packages
 c39c9e7aa83bbad644183f6debc02724              860 
main/binary-amd64/Packages.bz2
 29ebf0da941a3982a75772b16cf83ddd              706 main/binary-amd64/Packages.gz
 d14dd7acdcef58e0e2948f808abb3a31             2154 main/binary-i386/Packages
 c39c9e7aa83bbad644183f6debc02724              860 main/binary-i386/Packages.bz2
 29ebf0da941a3982a75772b16cf83ddd              706 main/binary-i386/Packages.gz
SHA1:
 44898d38972f335a1feacafb5454db519fa736e7             2154 
main/binary-all/Packages
 1c1a0dfe332475028497b971a0bb1afb88a417d5              860 
main/binary-all/Packages.bz2
 e332c6b43880cb4c26af408626748c702a230d10              706 
main/binary-all/Packages.gz
 44898d38972f335a1feacafb5454db519fa736e7             2154 
main/binary-amd64/Packages
 1c1a0dfe332475028497b971a0bb1afb88a417d5              860 
main/binary-amd64/Packages.bz2
 e332c6b43880cb4c26af408626748c702a230d10              706 
main/binary-amd64/Packages.gz
 44898d38972f335a1feacafb5454db519fa736e7             2154 
main/binary-i386/Packages
 1c1a0dfe332475028497b971a0bb1afb88a417d5              860 
main/binary-i386/Packages.bz2
 e332c6b43880cb4c26af408626748c702a230d10              706 
main/binary-i386/Packages.gz
SHA256:
 6a7e79cd5a3619255d8f304a3870c66f8a58c9deca490b4a08ce2ae69a2b3c84             
2154 main/binary-all/Packages
 dcc398c50f740ec627476c492702fd1fa21490b44fe88de64970a6f174d372f2              
860 main/binary-all/Packages.bz2
 0cac69595f66c9cebabcd36f4215aa31371241bebc57ae4a497a9fdc0c7a1d82              
706 main/binary-all/Packages.gz
 6a7e79cd5a3619255d8f304a3870c66f8a58c9deca490b4a08ce2ae69a2b3c84             
2154 main/binary-amd64/Packages
 dcc398c50f740ec627476c492702fd1fa21490b44fe88de64970a6f174d372f2              
860 main/binary-amd64/Packages.bz2
 0cac69595f66c9cebabcd36f4215aa31371241bebc57ae4a497a9fdc0c7a1d82              
706 main/binary-amd64/Packages.gz
 6a7e79cd5a3619255d8f304a3870c66f8a58c9deca490b4a08ce2ae69a2b3c84             
2154 main/binary-i386/Packages
 dcc398c50f740ec627476c492702fd1fa21490b44fe88de64970a6f174d372f2              
860 main/binary-i386/Packages.bz2
 0cac69595f66c9cebabcd36f4215aa31371241bebc57ae4a497a9fdc0c7a1d82              
706 main/binary-i386/Packages.gz
mshuler@hana:~/tmp$ 
mshuler@hana:~/tmp$ cat apache-ignite_Packages
Package: apache-ignite
Version: 2.5.0-1
Architecture: all
Maintainer: Petr Ivanov <[email protected]>
Installed-Size: 431627
Depends: openjdk-8-jdk | oracle-java8-installer, systemd, passwd
Section: misc
Priority: optional
Homepage: https://ignite.apache.org
Description: Apache Ignite In-Memory Computing, Database and Caching Platform
 Ignite™ is a memory-centric distributed database, caching, and processing
 platform for transactional, analytical, and streaming workloads, delivering
 in-memory speeds at petabyte scale
Filename: pool/main/a/apache-ignite_2.5.0-1_all.deb
SHA1: 195250498165ef905dc0f43660d0f2134618e16b
SHA256: 5b83273354a7f8bc59a740737518a9458fbc0172e845fda5a54f744e03d6f0a3
Size: 297016414

Package: apache-ignite
Version: 2.6.0-1
Architecture: all
Maintainer: Petr Ivanov <[email protected]>
Installed-Size: 386734
Depends: openjdk-8-jdk | oracle-java8-installer, systemd, passwd
Section: misc
Priority: optional
Homepage: https://ignite.apache.org
Description: Apache Ignite In-Memory Computing, Database and Caching Platform
 Ignite™ is a memory-centric distributed database, caching, and processing
 platform for transactional, analytical, and streaming workloads, delivering
 in-memory speeds at petabyte scale
Filename: pool/main/a/apache-ignite_2.6.0-1_all.deb
SHA1: 78e51929ed2b698ebd78baf57878befdbe014f7c
SHA256: 4e11429b53a09b31e5c812b2e22f2185826f65793ddd344f7688f7d1dc132335
Size: 256947944

Package: apache-ignite
Version: 2.7.0-1
Architecture: all
Maintainer: Petr Ivanov <[email protected]>
Installed-Size: 435467
Depends: openjdk-8-jdk | oracle-java8-installer, systemd, passwd
Section: misc
Priority: optional
Homepage: https://ignite.apache.org
Description: Apache Ignite In-Memory Computing, Database and Caching Platform
 Ignite™ is a memory-centric distributed database, caching, and processing
 platform for transactional, analytical, and streaming workloads, delivering
 in-memory speeds at petabyte scale
Filename: pool/main/a/apache-ignite_2.7.0-1_all.deb
SHA1: b0614afb8d2a6a7ef4b8d5b8bbba34f3a03dcd8c
SHA256: 52cc750e8e2723659ee19115ac03b98f05789714a9fadb1dda4eb0ea7e150dcb
Size: 289163874
{noformat}

There are quite a few more example repositories that can be browsed from the 
first org link, if someone wants to continue digging in them all to see who 
signed what. In this particular example, the generic "sign my repo with the 
bintray key" appears to be in active use. INFRA had to link my github account 
to allow me to upload to the cassandra bintray repo, so there's authentication 
& authorization for who can upload.

> Investigate GPG signing of deb and rpm repositories via bintray
> ---------------------------------------------------------------
>
>                 Key: CASSANDRA-14968
>                 URL: https://issues.apache.org/jira/browse/CASSANDRA-14968
>             Project: Cassandra
>          Issue Type: Bug
>            Reporter: Michael Shuler
>            Priority: Major
>              Labels: packaging
>
> Currently, the release manager uploads debian packages and built/signed 
> metadata to a generic bintray repository. Perhaps we could utilize the GPG 
> signing feature of the repository, post-upload, via the bintray GPG signing 
> feature.
> https://www.jfrog.com/confluence/display/BT/Managing+Uploaded+Content#ManagingUploadedContent-GPGSigning
>  Depends on CASSANDRA-14967



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to