Sunday, March 11, 2012

RPM Signing / Yum Repo

In this post I will be going through the steps on how to sign packages with your own keys as well as making your own repository that can be used to distribute your signed keys to other people.

First I will be making the gpg key that will be used to sign the package, the first command is "gpg --gen-key", after you type that command in it will ask you some questions. Here is a small clip of my output. 

[chris@localhost ~]$ gpg --gen-key
gpg (GnuPG) 1.4.11; Copyright (C) 2010 Free Software Foundation, Inc.
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.

gpg: directory `/home/chris/.gnupg' created
gpg: new configuration file `/home/chris/.gnupg/gpg.conf' created
gpg: WARNING: options in `/home/chris/.gnupg/gpg.conf' are not yet active during this run
gpg: keyring `/home/chris/.gnupg/secring.gpg' created
gpg: keyring `/home/chris/.gnupg/pubring.gpg' created
Please select what kind of key you want:
   (1) RSA and RSA (default)
   (2) DSA and Elgamal
   (3) DSA (sign only)
   (4) RSA (sign only)
Your selection? 1

for the most part I left all the options as default.

Now that my key is made, I need to make some changes to the ~/.rpmmacros file, all I needed to do was add this line to the bottom.

%_gpg_name "email used in gpg key making"

With that done we can now start to sign packages, first make sure you install this first in order for the signing to work

yum install rpm-sign

After that is done use this command I used the yumdownloader command to get my package and the next command to sign the package

yumdownloader gcal

rpm --addsign gcal-3.6-3.fc16.x86_64.rpm

Next, with the package signed with my key we can now make the YUM repository, I am using http to host my repository so I moved my sign package to the /var/www/html folder. Then I ran this command to make the repository metadata for my package

createrepo .

Now besides the signed package there should be a repodata folder, this is it for creating the YUM repo.

The last part is making repo file, for this I copied one of the existing repos in the /etc/yum.repos.d in the repo directory and modified it to something like this.

[chris]
name=Chris $releasever - $basearch
baseurl=http://matrix.senecac.on.ca/~cchoo2/chrisrepo
#mirrorlist=https://mirrors.fedoraproject.org

#/metalink?repo=fedora-$releasever&arch=$basearch
enabled=1
metadata_expire=7d
gpgcheck=1
gpgkey=file:///etc/pki/rpm-gpg/chrischoo-gpg-key-rpm


To get the proper gpgkey to authenticate the package when you install is you have to do some things first:

gpg --export --armour "email used in gpg key making" > chrischoo-gpg-key-rpm
(exports my gpg key to the /etc/pki/rpm-gpg location to the file that I made
there)

Also in your repo file change the last line so it points to your key 
gpgkey=file:///etc/pki/rpm-gpg/chrischoo-gpg-key-rpm

With that done now you should be able to install your signed package.

I created an RPM that you can download to add my repository and gpg key so you can download my signed gcal rpm

Repo RPM

Here are some screen shots of my repository in action.





No comments:

Post a Comment