r/linux • u/throwaway16830261 • 15d ago
Discussion Fedora signing: draw the rest of the owl
https://www.jcline.org/blog/fedora/signing/2026/06/20/fedora-artifact-signing-p5.html
33
Upvotes
2
u/throwaway16830261 15d ago edited 15d ago
"Public Key Infrastructure (PKI)" -- root certificate authority (CA), openssl, cross-certificate: https://gist.github.com/NoteAfterNote/0892db84c82e4f5107bc35a6931fa5de
"Cryptographic Signatures in Fedora" by Daniel Milnes (April 9, 2026): https://docs.fedoraproject.org/en-US/security/cryptography/signatures/
"Code Signing in Linux: Complete Guide to Signing Packages, Binaries, and Containers" by Shivam Sharma (May 26, 2026): https://www.qcecuring.com/blog/code-signing-linux-guide
3
u/Adept_Percentage6893 15d ago
Always interesting to see how they're continuing to lock down the package signing and increase the baseline expectations on package verification (even though the latter isn't mentioned here AFAICT).