Skip to content

Support Signing with passphrase protected GPG Keys #1544

@voigt

Description

@voigt

Description

Signing a component via ocm sign componentversion does not offer an option to provide a passphrase protected GPG key, which prevents reusing existing key material in some cases. I therefore request a feature for handling GPG keys which are passphrase protected.

Rationale

The OpenBao project wants to start distributing OpenBao artifacts via OCM (see #74).

For artifact signing the project usually uses a passphrase protected GPG key. With a lack of this feature, we are unable to reuse our well known and trusted key.

Metadata

Metadata

Labels

area/ipceiImportant Project of Common European Interestdev/help-wantedNeeds help by someone elsekind/featurenew feature, enhancement, improvement, extensionlifecycle/staleNobody worked on this for 6 months (will further age)
No fields configured for Feature.

Projects

Status
🍺 Done

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions