Don’t do GPG signature checking on Fedora and derivatives #126
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Fedora are aiming to enforce GPG signature checking on all RPM packages. We don’t sign our packages, so that will fail.
https://fedoraproject.org/wiki/Changes/Enforcing_signature_checking_by_default
A better solution would, of course, be to actually sign the packages and distribute the keys, perhaps even via our own Yum repository. Better still would be to get LMS included in Fedora, but for that we need to unbundle any remaining non-free firmware and, ideally, switch to upstream versions of all bundled CPAN modules.
We don't need to make this change until Fedora 44 releases in April 2026, but I'm raising this now before I forget. It looks like it won't even work until rpm-software-management/dnf5#2479 is fixed.