-
Notifications
You must be signed in to change notification settings - Fork 220
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Installers signed and hashed with algo like >=SHA256 #344
Comments
Hi, All our rpms are signed with our GPG key. We are signing with a 4096 RSA key using SHA256 signatures
You can quickly check that
|
See also corretto-17 #29 |
I am sorry that the problem description was not accurate: Our customer requires to have the file digest SHA256 instead of MD5. Otherwise we are not compliant. We use the following setting in .rpmmacros file: Bus as I see nebula ospackage plugin does not support this option yet. |
Hi, We will have to update our build to use a newer version of the plugin, at least v8.6.1. https://github.com/nebula-plugins/gradle-ospackage-plugin/releases/tag/v8.6.1 |
This is fixed in #345 and RPMs should use SHA256 for digest after the Q1 2022 release. |
Is your feature request related to a problem?
Our customer requires us to have all RPM installers signed and hashed with strong hasing algo like SHA256. Otherwise we are not compliant.
Describe a solution you would like
Installers signed and hashed with SHA256 or stronger.
Describe alternatives you have considered
N/A
Additional context
US Department of Defense and many other customers are security aware and want to protect their deployments.
The text was updated successfully, but these errors were encountered: