[PATCH] Hardening: add signature check with rpmcliVerifySignatures
authorAleš Matěj <amatej@redhat.com>
Mon, 29 Mar 2021 07:22:09 +0000 (09:22 +0200)
committerFrédéric Pierret <frederic.pierret@qubes-os.org>
Wed, 14 Apr 2021 19:26:57 +0000 (20:26 +0100)
commit0393ec55a35e4059fd70f86070ff20ba02eed1d1
tree79db40da94d2e08dab79aafd1a403a8dfaca08d0
parent6440ef50c9eb07bebcfae443b2ca20075fcc6c6a
[PATCH] Hardening: add signature check with rpmcliVerifySignatures

This api is not ideal but works for now. We don't have to set
installroot for the used transaction because we set keyring which is
used to retrieve the keys.

= changelog =
msg: Hardening: add signature check with rpmcliVerifySignatures
type: security
resolves: https://bugzilla.redhat.com/show_bug.cgi?id=1932079

CVE-2021-3445
RhBug:1932079
RhBug:1932089
RhBug:1932090

Related: CVE-2021-3421, CVE-2021-20271

Gbp-Pq: Name 0014-Hardening-add-signature-check-with-rpmcliVerifySigna.patch
libdnf/dnf-keyring.cpp