Fedora GPG signing/verifying question

2019-03-28 Thread Michael Zhang
Hi,When publishing, does Fedora:     a) rebuild a maintainer's package from source and gpg sign it with their own fedora gpg key               (ex. /etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-11-primary) OR:      b) publish the package that the maintainer personally compiled and gpg signed with their perso

Re: Fedora GPG signing/verifying question

2019-03-28 Thread Michael Zhang
Thanks for the response.     Michael Zhang    Software Developer Test (WAS Install Team) Phone: 1-9054133415 E-mail: michael.zh...@ibm.com         - Original message -From: Tom Hughes To: Development discussions related to Fedora , Michael Zhang Cc:Subject: Re: F

Re: Fedora GPG signing/verifying question

2019-03-28 Thread Tom Hughes
On 28/03/2019 16:24, Michael Zhang wrote: When publishing, does Fedora:      a) rebuild a maintainer's package from source and gpg sign it with their own fedora gpg key               (ex. /etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-11-primary) OR:      b) publish the package that the maintainer per