> So outsourcing the crypto to external gpg executable would be very welcome.

This isn’t going to happen because spawning an external program breaks in too 
many situations.

> We can live with rpm verification disabled too.

This is a terrible idea from a security perspective.

-- 
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/issues/2414#issuecomment-1826160579
You are receiving this because you are subscribed to this thread.

Message ID: <rpm-software-management/rpm/issues/2414/1826160...@github.com>
_______________________________________________
Rpm-maint mailing list
Rpm-maint@lists.rpm.org
http://lists.rpm.org/mailman/listinfo/rpm-maint

Reply via email to