[CentOS-devel] repo_gpgcheck for centos repos?

Leon Fauster

leonfauster at googlemail.com
Thu Sep 3 19:40:48 UTC 2020


I wonder if it would be not beneficial enabling repo_gpgcheck for all 
centos repos?  A short cross check shows that also SIG repos have 
repomd.xml signed. mirror.centos.org has no TLS enabled and 
repo_gpgcheck would add an additional security layer per default?
This could be started for EL8? Or are there any barries?


More information about the CentOS-devel mailing list