RedHatOfficial / odie

ODIE - OpenShift Disconnected Installer for Enterprise.
GNU General Public License v2.0
27 stars 7 forks source link

Improve RPM repository signing #17

Open mike4263 opened 5 years ago

mike4263 commented 5 years ago

Right now the repo is created via the "download-custom-repo.sh" script.

There needs to be an operation that performs the rsync, creates the repo, then signs it. This should happen during odie stage. It should also work with both initial updates and incremental patch releases

mike4263 commented 5 years ago

In the interim, I have disabled repo gpg checking on the repository. This is a STIG finding.