Re: Packages and Signatures, a summary


I disagree with this. dpkg should have some rudimentary support to verify a
signature. I might want to use this feature on a machine where I don't have
apt installed, or on a platform where apt is not ported to. If apt can
support advanced features, that's nice, but dpkg is still our central
packaging system, and should support all critical features.

At least options to extract the signature from the package, and a script to
automatically check the signature with a given keyring are necessary, I think.


