public inbox for isar-users@googlegroups.com
 help / color / mirror / Atom feed
* [PATCH 0/3] Signing local cache repo
@ 2019-02-04 19:54 Maxim Yu. Osipov
  2019-02-04 19:54 ` [PATCH 1/3] isar-bootstrap: Allow to set local keys in DISTRO_APT_KEYS Maxim Yu. Osipov
                   ` (3 more replies)
  0 siblings, 4 replies; 5+ messages in thread
From: Maxim Yu. Osipov @ 2019-02-04 19:54 UTC (permalink / raw)
  To: isar-users

Hello everybody,

By default the local caching repo is not gpg signed.
This series adds the ability to sign it.  

Prerequsite: we suppose that gpg is installed on your host system
and a default key pair is generated.

 -  set `BASE_REPO_KEY` in `conf/local.conf` to `SRC_URI` of your public key,
f.e. BASE_REPO_KEY = "file:///home/user/my_pub.key" and 
follow usual procedure of  creation of local apt repo caching: 

 - bitbake -c cache_base_repo multiconfig:qemuamd64-stretch:isar-image-base

 - Set `ISAR_USE_CACHED_BASE_REPO` in `conf/local.conf`:

```
# Uncomment this to enable use of cached base repository
#ISAR_USE_CACHED_BASE_REPO ?= "1"
```
 - Remove build artifacts to use only local base-apt:

```
sudo rm -rf tmp

```
 - Trigger again generation of image (now using local caching repo):

```
bitbake multiconfig:qemuamd64-stretch:isar-image-base
```

Note: Depending on your gpg configuration you may be asked to provide a passphrase 
(if it is non empty).

Kind regards,
Maxim.

Maxim Yu. Osipov (3):
  isar-bootstrap: Allow to set local keys in DISTRO_APT_KEYS
  base-apt: Introduce BASE_REPO_KEY to sign local repo
  doc/user_manual: Describe gpg signing of local repo

 doc/user_manual.md                                  | 10 ++++++----
 meta/recipes-core/isar-bootstrap/isar-bootstrap.inc | 16 ++++++++++++++--
 meta/recipes-devtools/base-apt/base-apt.bb          |  6 ++++++
 3 files changed, 26 insertions(+), 6 deletions(-)

-- 
2.11.0


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2019-02-08 14:32 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2019-02-04 19:54 [PATCH 0/3] Signing local cache repo Maxim Yu. Osipov
2019-02-04 19:54 ` [PATCH 1/3] isar-bootstrap: Allow to set local keys in DISTRO_APT_KEYS Maxim Yu. Osipov
2019-02-04 19:54 ` [PATCH 2/3] base-apt: Introduce BASE_REPO_KEY to sign local repo Maxim Yu. Osipov
2019-02-04 19:54 ` [PATCH 3/3] doc/user_manual: Describe gpg signing of " Maxim Yu. Osipov
2019-02-08 14:32 ` [PATCH 0/3] Signing local cache repo Maxim Yu. Osipov

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox