serhepopovych / simple-cdd-meta

Debian and it's derivatives Simple-CDD preseed configuration with profiles
MIT License
6 stars 3 forks source link

Make ISO image repository Release files signed with project PGP/GPG keys #5

Open serhepopovych opened 4 years ago

serhepopovych commented 4 years ago

Tool for creating Debian mirror to be put to ISO has option to sign Release file and since local mirror has different set of packages and filesystem paths regular Debian Release.gpg cannot be reused. See reprepro(1) for more information on how to sign repository with PGP/GPG.

This is critically important for network setups (PXE). Currently we bypass repository signature checks using debian-installer/allow_unauthenticated=true preseed given on pxelinux command line.