Adding signatures is in fact a great feature in my view, as it allows to 
additionally validate by 3rd parties that a package is ok to be consumed 
withtout having to completely remove the original signatures.

For example: Linux vendor releases package XYZ-1.2.3 signed with RSA and 
SLH-DSA, later on Vendor Z-ACME release their own derived distribution and just 
adds a signature with their key of type ML-DSA. The ability to add additional 
signatures is actually a feature in RPM.
It does not detract from the existing signatures either which can still be 
check to trace that yeas the package was not altered by Z-ACME, only further 
validated as part of their package set.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/issues/2224#issuecomment-2512803821
You are receiving this because you are subscribed to this thread.

Message ID: <rpm-software-management/rpm/issues/2224/2512803...@github.com>
_______________________________________________
Rpm-maint mailing list
Rpm-maint@lists.rpm.org
https://lists.rpm.org/mailman/listinfo/rpm-maint

Reply via email to