Skip to content

Add securedrop-workstation-dom0-config-0.7.1#40

Merged
eaon merged 2 commits intomainfrom
release-securedrop-workstation-dom0-config-0.7.1
Nov 29, 2022
Merged

Add securedrop-workstation-dom0-config-0.7.1#40
eaon merged 2 commits intomainfrom
release-securedrop-workstation-dom0-config-0.7.1

Conversation

@gonzalo-bulnes
Copy link
Contributor

@gonzalo-bulnes gonzalo-bulnes commented Nov 29, 2022

Description

Name of package: securedrop-workstation-dom0-config-0.7.1

Test plan

@eaon
Copy link
Contributor

eaon commented Nov 29, 2022

After a bit of a longer journey into signing and verifying the dev-env only release for the workstation, @gonzalo-bulnes and I stumbled over something unfortunate but glad we stumbled now:

It looks as if our whole add signature/delete signature to reverify the RPM sha256sum does not work on bullseye anymore. It works on buster tho 😭 However, we consistently get the same hash for the package where the signature was removed once on Debian 11 and Fedora 36/37 - if we resign it and remove it again the sum changes once more but consistently (again … how weird is that). @gonzalo-bulnes and I think there's probably a deeper conversation about reproducible builds embedded in this, but we're OK with having it work in buster for this dev-env only type situation for now.

PS: the gpg argument order in the docs are wrong, --output … can't be the last argument. PR incoming for that one.

@eaon eaon merged commit 61d2d54 into main Nov 29, 2022
@legoktm legoktm deleted the release-securedrop-workstation-dom0-config-0.7.1 branch March 10, 2023 22:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants