Using gpg to add digital signature to a linux executable

Andrew Marlow marlow.agents at gmail.com
Tue Oct 26 17:08:56 CEST 2021


Hello everyone,

For some time now where I work there has been a rule saying "thou shalt add
a digital signature to every executable and shared library when shipping
software designed to run on Windows". This is quite doable and all is well
and good. At least, on Windows. But what about linux? The only thing I've
seen for linux is to create separate digital signatures using tools like
gpg (GNU Privacy Guard). I can find no mention of how to attach them to an
executable or shared library. Has anyone here ever done anything like this
please? It seems to me there is real benefit in doing it. So, much as I
detest Windows, this seems to be one area in which Windows is slightly
ahead.

-- 
Regards,

Andrew Marlow
http://www.andrewpetermarlow.co.uk
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.gnupg.org/pipermail/gnupg-users/attachments/20211026/bf80d7b1/attachment-0001.html>


More information about the Gnupg-users mailing list