buildds: force SHA512 signatures
authorAurelien Jarno <aurelien@aurel32.net>
Sat, 16 Jan 2016 17:25:48 +0000 (18:25 +0100)
committerAurelien Jarno <aurelien@aurel32.net>
Sat, 16 Jan 2016 17:25:48 +0000 (18:25 +0100)
Provide a ~/.gnupg/gpg.conf on the buildds to force SHA512 signatures.
Otherwise gpg still uses to SHA1 by default...

Signed-off-by: Aurelien Jarno <aurelien@aurel32.net>
modules/buildd/manifests/init.pp

index b58bd01..7b22eae 100644 (file)
@@ -179,6 +179,17 @@ class buildd ($ensure=present) {
                group   => buildd,
                owner   => buildd,
        }
+       file { '/home/buildd/.gnupg':
+               ensure  => directory,
+               mode    => '700',
+               group   => buildd,
+               owner   => buildd,
+       }
+       file { '/home/buildd/.gnupg/gpg.conf':
+               content  => "personal-digest-preferences SHA512\n",
+               group   => buildd,
+               owner   => buildd,
+       }
 
        if ! $::buildd_key {
                exec { 'create-buildd-key':