#!/bin/sh OPKG_KEYS="${OPKG_KEYS:-/etc/opkg/keys}" usage() { cat < Commands: add : Add keyfile to opkg trusted keys remove : Remove keyfile matching from opkg trusted keys verify : Check list file against signature file EOF exit 1 } opkg_key_verify() { local sigfile="$1" local msgfile="$2" ( zcat "$msgfile" 2>/dev/null || cat "$msgfile" 2>/dev/null ) | usign -V -P "$OPKG_KEYS" -q -x "$sigfile" -m - } opkg_key_add() { local key="$1" [ -n "$key" ] || usage [ -f "$key" ] || echo "Cannot open file $1" local fingerprint="$(usign -F -p "$key")" mkdir -p "$OPKG_KEYS" cp "$key" "$OPKG_KEYS/$fingerprint" } opkg_key_remove() { local key="$1" [ -n "$key" ] || usage [ -f "$key" ] || echo "Cannot open file $1" local fingerprint="$(usign -F -p "$key")" rm -f "$OPKG_KEYS/$fingerprint" } case "$1" in add) shift opkg_key_add "$@" ;; remove) shift opkg_key_remove "$@" ;; verify) shift opkg_key_verify "$@" ;; *) usage ;; esac