#469246 [dget] Please add an option to use a specific keyring for dsc verification

Package:
devscripts
Source:
devscripts
Description:
scripts to make the life of a Debian Package maintainer easier
Submitter:
Date:
2021-09-22 04:44:43 UTC
Severity:
wishlist
#469246#5
Date:
2008-03-04 06:53:27 UTC
From:
To:
I would like an option I can put in my ~/.devscripts and use on the
command line to make dget verify signatures using my regular gpg keyring
as well as the debian-keyring. Alternatively change dscverify to check
~/.gnupg/pubring.gpg but print out a warning if the key is not in
debian-keyring.

#469246#10
Date:
2008-03-04 07:44:10 UTC
From:
To:
Is this an option that you'd only want to use when dget is calling
dscverify, or any time that dscverify is called? If the latter then the
functionality already exists (DSCVERIFY_KEYRINGS).

This is already possible (see above) but I'm not convinced we'd want to
include it by default.

This, otoh, is not currently supported. I suppose one could have
dscverify call check_signature() twice with different keyrings.

Adam

#469246#15
Date:
2008-03-04 09:28:32 UTC
From:
To:
My use-case is downloading packages from mentors.d.n for sponsorship,
there I always use dget rather than dscverify. I reported this bug
because dget -x wasn't working as it used to because it now calls
dscverify, fails and decides not to run dpkg-source. Perhaps what I
really want is for dget -x to run dpkg-source -x even if dscverify
fails. That way I get to see a warning from dpkg-source if the key isn't
in my keyring or the package has been tampered with in transit.

Thinking about it more, I'd like -x to do these:

      * good DD sig: yay, unpack
      * bad DD sig: big error, option to force unpack
      * good DM sig: yay, unpack, inform me of DM status
      * bad DM sig: big error, option to force unpack
      * good other sig: yay, unpack, inform me of otherness
      * bad other sig: big, option to force unpack
      * no sig: yay, unpack, warn about no sig

With no -x would just do the same without unpacking.

Fair enough.

Sounds fine to me.

#469246#20
Date:
2008-03-22 21:22:18 UTC
From:
To:
Re: Paul Wise 2008-03-04 <1204622912.32309.9.camel@chianamo>

I think the keyring selection should be done via the dscverify config.

What we probably should support is a mode where unsigned packages are
unpacked, but where it still complains about bad signatures.

Christoph

#469246#25
Date:
2010-04-04 02:35:21 UTC
From:
To:
This is already supported in that if you use -u, “dpkg-source -x” will
complain about the bad signature, but still unpack.  The issue is that
dscverify differs from dpkg-source and stops hard when there's a bad
signature.

It sounds like Paul's request is satisfied by using DGET_VERIFY=no as
that will fall through to dpkg-source.  dpkg-source only uses
~/.gnupg/trustedkeys.gpg though, so maybe this should turn into a
wishlist dpkg-dev bug for supporting ~/.gnupg/pubring.gpg or
specification of arbitrary keyring files?

#469246#30
Date:
2021-09-22 04:22:54 UTC
From:
To:
Hello,

Good morning,

We have gone through your samples from a partner and Here is our  Order
List. Please do bear in mind that we are very much in  need of this
order, quote your competitive prices.

Kindly send the Order confirmation.

Your early reply will be much appreciated.

Best Regards,

Maryanah Erwin.

PT FINDORA INTERNUSA

Jln Pahlawan 66 Kec. Arjawinangun

45162 CIREBON West-Java INDONESIA

tel : +62 231 357334

fax: +62 231 357260

email: marketing@findora.com