-
Notifications
You must be signed in to change notification settings - Fork 1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Use --allow-weak-hashes
instead of disabling signature verification entirely
#6
Comments
@DemiMarie That sounds great, what is |
It’s a Rust tool for canonicalizing RPM packages, verifying the signatures, and stripping anything nasty in them. Qubes OS uses it for all dom0 updates and for all calls to |
Is it possible to get qubes-update-dom0 to pass |
Not directly, though one can patch |
openzfs/zfs#13176 (comment) |
Yup! Time to turn signature verification back on! |
rpmcanon provides the
--allow-weak-hashes
argument to allow packages signed with SHA-1 to be installed, which is (much) better than turning off signature verification.The text was updated successfully, but these errors were encountered: