The Fedora signing key issue – a plan for users


If you hadn't heard, Fedora and Red Hat systems had a break in of sorts that impacted their software repositories. I don't quite understand the details but apparently nothing bad happened except that they need to create a new gpg key to sign their software packages. That means that all packages on all fedora systems (possibly on Fedora 9, but maybe older supported versions as well) will eventually have to be migrated to the new signing key.

I wasn't sure how this was supposed to work, but Kevin Fenzi over at tummy.com (who works on the fedora project) pointed me to the LWN.net posting that linked to Fedora's plan for this. So I'll try to keep track with lwn.net on the issue to find out when I'm supposed to be updating my systems. Hopefully they'll get the details worked out so we don't get too far behind in security updates.

I should really be on the Fedora Announce mailing list, though, if I want to really keep up to date.