Admin message

Due to an influx of spam, we have had to temporarily disable account registrations. Please write an email to accountsupport@archlinux.org, with your desired username, if you want to get access. Sorry for the inconvenience.

Open
Milestone

Sign high impact artifacts

All package files are currently signed by individual package maintainers. Automating the signing of package files implies, that an automated, central build system provides a secure way of delegating the signing operation to the Signstar system. Signing the package files is considered a high impact action, because signing these artifacts happens on a high cadence and all Arch Linux users rely on signature verification of package files by default already.

To allow for this target to be met, an automated build system (e.g. buildbtw) must provide secure means of authenticating against the Signstar host. Each host in such a central system should guard its SSH key used for connecting to the Signstar host using the host’s integrated or discrete TPM 2.0.

Once signing of package files is automated and works reliably, the per package maintainer OpenPGP certificates in archlinux-keyring should be decommissioned by revoking the third-party signatures issued by the distribution-specific trust anchors.

  • Work items 0
  • Merge requests 0
  • Participants 0
  • Labels 0
Loading
Loading
Loading
Loading
0% complete
0%
Start date
No start date
None
Due date
No due date
0
Work items 0 New issue
Open: 0 Closed: 0
None
Total weight
None
0
Merge requests 0
Open: 0 Closed: 0 Merged: 0
0
Releases
None
Reference: archlinux/signstar%"Sign high impact artifacts"