Hmm, perhaps I need to clarify this: I don't mean signing the other OpenPGP 
signatures, but the other content in the so called signature header: digests 
and arrays of file-level signatures which are "free-standing" at the moment: 
you can modify them without rpm noticing at all. I suppose you can't install 
file signatures the kernel doesn't trust, but you could eg remove signatures 
from some files, allegedly to some consequences. It seems a little fishy at 
best.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/issues/2224#issuecomment-2513581158
You are receiving this because you are subscribed to this thread.

Message ID: <rpm-software-management/rpm/issues/2224/2513581...@github.com>
_______________________________________________
Rpm-maint mailing list
Rpm-maint@lists.rpm.org
https://lists.rpm.org/mailman/listinfo/rpm-maint

Reply via email to