Re: improving downloader packages (was: Re: holes in secure apt)
Raphael Hertzog dijo [Fri, Jun 20, 2014 at 09:17:25AM +0200]:
> > FWIW, I was thinking about including the possible disappearance as one
> > of the points to talk about in the DebConf BoF we proposed regarding
> > keyring-maint.
>
> Why not switch it to something more dynamic ?
>
> Make the package an empty shell with symlinks pointing to
> /var/lib/debian-keyring/, add a cron job that rsyncs the keyring
> to that directory.
Why not prompt users to clone the public git tree instead? :)
Reply to: