In Fedora 44, there are plans to enable digital signature package verification in RPM.

In the upcoming release of Fedora Linux 44, scheduled for spring 2026, digital signature verification for RPM packages is set to be enabled by default. If the plan is approved by the FESCo (Fedora Engineering Steering Committee), responsible for the technical aspects of Fedora Linux development, only packages with a valid digital signature will be able to be installed by default. If manual installation of packages is necessary, a bypass option will be available by explicitly running RPM with the "--nosignature" flag or disabling verification through the corresponding API.

The functionality for verifying packages by digital signature was implemented in the RPM package manager 6.0, but in Fedora 43, despite transitioning to RPM 6, only hash integrity checks are used at the RPM level, while the authenticity of packages from repositories is verified at the high-level package managers YUM and DNF, where the ability to verify by digital signatures was originally implemented and enabled by default. Now similar verification is intended to be employed at the RPM level. If the change is approved in Fedora 44, both integrity checking via hash and authenticity checking via a digital signature signed by the package builder's key will be performed when installing packages via RPM.

When attempting to install packages without a signature or with an incorrect signature, an error will be displayed by default unless the user explicitly runs rpm with the "--nosignature" flag. To work with external repositories that do not generate digital signatures, selective disabling of RPM verification for specific packages has been added to the DNF 5.2.14.0 package manager. This ability has been incorporated into the Mock (mock-core-configs) toolkit for working with new package builds. A plugin for generating signatures for locally built packages has also been added to Mock, and the Copr (Community projects) service has implemented the ability to automatically generate signatures.

Additionally, it is worth noting the confirmed release date for Fedora 43, which will take place on October 28.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster