Actions
Bug #21069
closedyum repo foreman-plugins installed with no security
Status:
Duplicate
Priority:
Normal
Assignee:
-
Category:
RPMs
Target version:
-
Description
foreman-release
installs foreman-plugins
yum repo with gpgcheck=0
and baseurl
with plain HTTP.
If gpg-signing packages is not feasible, then at least using HTTPS instead of plain HTTP would improve system's security with regard to installing/updating those packages.
Actions