Skip to content

Support Signing with passphrase protected GPG Keys #1544

@voigt

Description

@voigt

Description

Signing a component via ocm sign componentversion does not offer an option to provide a passphrase protected GPG key, which prevents reusing existing key material in some cases. I therefore request a feature for handling GPG keys which are passphrase protected.

Rationale

The OpenBao project wants to start distributing OpenBao artifacts via OCM (see #74).

For artifact signing the project usually uses a passphrase protected GPG key. With a lack of this feature, we are unable to reuse our well known and trusted key.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/ipceiImportant Project of Common European Interestdev/help-wantedNeeds help by someone elsekind/featurenew feature, enhancement, improvement, extension

    Projects

    Status

    📋 Next-UP

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions