Updates make DVD upgrade insecure. (was: AutoQA upgrade path failure makes no sense to me)
Kevin Kofler wrote:
> I've been saying all the time that the DVD must get
> fixed to support enabling the updates repository also for upgrades, not
> just for new installs. In fact, I'd even go as far as saying it should
> REQUIRE it, not just support it.
That would make bug 998 even more urgent than it already is – especially if
the updates repository were required, as that would change the upgrade from
secure to insecure. Currently it is possible to upgrade by DVD in a secure
way. It requires some manual checking but it can be done if you have the
knowledge. If packages are downloaded during the upgrade, then the upgrade is
insecure unless Anaconda learns to verify the signatures on the packages it
downloads.
Björn Persson
--
devel mailing list
devel@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/devel