Last modified: 2014-05-02 11:51:37 UTC

Wikimedia Bugzilla is closed!

Wikimedia migrated from Bugzilla to Phabricator. Bug reports are handled in Wikimedia Phabricator.
This static website is read-only and for historical purposes. It is not possible to log in and except for displaying bug reports and their history, links might be broken. See T64391, the corresponding Phabricator task for complete and up-to-date bug report information.
Bug 62391 - Jenkins needs the ability to sign tarballs
Jenkins needs the ability to sign tarballs
Status: NEW
Product: Wikimedia
Classification: Unclassified
Continuous integration (Other open bugs)
unspecified
All All
: Normal normal (vote)
: ---
Assigned To: Nobody - You can work on this!
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2014-03-07 17:06 UTC by Mark A. Hershberger
Modified: 2014-05-02 11:51 UTC (History)
6 users (show)

See Also:
Web browser: ---
Mobile Platform: ---
Assignee Huggle Beta Tester: ---


Attachments

Description Mark A. Hershberger 2014-03-07 17:06:32 UTC
We need the ability to sign tarballs automatically.  Using this ticket to track what needs to be done and by whome.  Assigning to Antoine for now since he is the Jenkins guy.
Comment 1 Chris Steipp 2014-03-07 18:25:46 UTC
Since we've had a number of conversations around this, let me enumerate the options we've talked about. We probably need to just pick a strategy and try it:

1) The "Jenkins" who does the signing is a private/secured version where we feel comfortable keeping a private key.
2) We put the signing key in an hsm in the datacenter, and make sure someone audits/watches what is being signed.
3) Jenkins signs with a key only to say, "This is what Jenkins built". It's up to someone in the release process to verify and sign the tarballs to assert that someone is pretty sure the tarballs were built correctly.
Comment 2 Antoine "hashar" Musso (WMF) 2014-03-10 10:20:12 UTC
I do not have any free time in March to handle release tarballs / securing Jenkins.  If someone else can take the lead there that would be much appreciated.  We can most probably use a private Jenkins server for ops/analytics/mw tarball usage.  They all have the same need apparently.
Comment 3 Antoine "hashar" Musso (WMF) 2014-05-02 11:51:37 UTC
Resetting assignee, I am not working on this.

Note You need to log in before you can comment on or make changes to this bug.


Navigation
Links