[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Security guidelines for Debian people

]] Lars Wirzenius 

| Assuming we're talking about each developer's personal key: what
| things would they be signing that matter? Package upload signatures
| are relevant only until the upload gets accepted into the archive, and
| after that it's the archive signing key that matters.

Source packages are signed with the developer's key.

Tollef Fog Heen
UNIX is user friendly, it's just picky about who its friends are

Reply to: