- Package:
- devscripts
- Source:
- devscripts
- Description:
- scripts to make the life of a Debian Package maintainer easier
- Submitter:
- Date:
- 2021-09-22 04:44:43 UTC
- Severity:
- wishlist
I would like an option I can put in my ~/.devscripts and use on the command line to make dget verify signatures using my regular gpg keyring as well as the debian-keyring. Alternatively change dscverify to check ~/.gnupg/pubring.gpg but print out a warning if the key is not in debian-keyring.
Is this an option that you'd only want to use when dget is calling dscverify, or any time that dscverify is called? If the latter then the functionality already exists (DSCVERIFY_KEYRINGS). This is already possible (see above) but I'm not convinced we'd want to include it by default. This, otoh, is not currently supported. I suppose one could have dscverify call check_signature() twice with different keyrings. Adam
My use-case is downloading packages from mentors.d.n for sponsorship,
there I always use dget rather than dscverify. I reported this bug
because dget -x wasn't working as it used to because it now calls
dscverify, fails and decides not to run dpkg-source. Perhaps what I
really want is for dget -x to run dpkg-source -x even if dscverify
fails. That way I get to see a warning from dpkg-source if the key isn't
in my keyring or the package has been tampered with in transit.
Thinking about it more, I'd like -x to do these:
* good DD sig: yay, unpack
* bad DD sig: big error, option to force unpack
* good DM sig: yay, unpack, inform me of DM status
* bad DM sig: big error, option to force unpack
* good other sig: yay, unpack, inform me of otherness
* bad other sig: big, option to force unpack
* no sig: yay, unpack, warn about no sig
With no -x would just do the same without unpacking.
Fair enough.
Sounds fine to me.
Re: Paul Wise 2008-03-04 <1204622912.32309.9.camel@chianamo> I think the keyring selection should be done via the dscverify config. What we probably should support is a mode where unsigned packages are unpacked, but where it still complains about bad signatures. Christoph
This is already supported in that if you use -u, “dpkg-source -x” will complain about the bad signature, but still unpack. The issue is that dscverify differs from dpkg-source and stops hard when there's a bad signature. It sounds like Paul's request is satisfied by using DGET_VERIFY=no as that will fall through to dpkg-source. dpkg-source only uses ~/.gnupg/trustedkeys.gpg though, so maybe this should turn into a wishlist dpkg-dev bug for supporting ~/.gnupg/pubring.gpg or specification of arbitrary keyring files?
Hello, Good morning, We have gone through your samples from a partner and Here is our Order List. Please do bear in mind that we are very much in need of this order, quote your competitive prices. Kindly send the Order confirmation. Your early reply will be much appreciated. Best Regards, Maryanah Erwin. PT FINDORA INTERNUSA Jln Pahlawan 66 Kec. Arjawinangun 45162 CIREBON West-Java INDONESIA tel : +62 231 357334 fax: +62 231 357260 email: marketing@findora.com