[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#341976: patch



On Thu, Nov 23, 2006 at 12:21:01PM +0100, Flavio Stanchina wrote:
tags 341976 + patch
thanks

Here's a patch that adds a "get <keyid> <server>" command to apt-key.

This patch is dangerously insecure, since it does not perform any verification that the key that gets retrieved actually matches a trusted key fingerprint.

If you're going to do this at all, the correct thing to do is probably to require the user to enter the full 40-character (160-bit) key fingerprint as the key id.

--
Dwayne C. Litzenberger <dlitz@dlitz.net>




Reply to: