[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: why are improperly signed uploads accepted?



Robert Bihlmeyer <robbe@orcus.priv.at> writes:
> Ben Collins <bcollins@debian.org> writes:
> > Don't go by the debian-keyring package. It's not as up-to-date as the one
> > that dinstall uses.
> Ok, thanks! I didn't know about keyring.debian.org. I checked
> db.debian.org instead, and it still has Michael's old key. I will
> adapt my script to the keyring machine.

The key currently on the keyring was created with a broken copy of
gnupg.

When dinstall started dropping all my packages several weeks ago, I
ended up talking with James, and put a new key in---he presumably just
hasn't spun a new copy of the keyring package.

I did let him know I was no longer using the old key (as he
requested), so I'm assuming the next keyring will just have my new
key.

No as to why db.debian.org has my old key---I'm not sure I can change
that.  I'll look, though.

Mike.



Reply to: