#780280 dak: generate rejection mail for mails with expired signature

#780280#5
Date:
2015-03-11 15:20:07 UTC
From:
To:
It would be nice if dak would generate rejection mails for uploads that
have a valid signature, but where the signature is expired or from an
expired key.

daklib/gpg.py already has some support for differentiating between
expired and invalid signatures, but some bits are still missing.

Ansgar

#780280#10
Date:
2015-11-13 10:22:34 UTC
From:
To:
Ansgar Burchardt:

It would not only be nice, it would help not being trapped in very silly
situation: files uploaded with a valid signature but with an expired
key are not removed from the queue. That means teammates are unable to
sponsor the upload while waiting for the keyring to be updated.
It's not possible to remove them using dcut either as the key will still
be expired…

I would be grateful if you could properly REJECT uploads for such cases.

Thanks,

#780280#15
Date:
2017-08-06 11:41:02 UTC
From:
To:
Hello!

Currently, the uploader of a package using an expired key is left
guessing as to why the package was accepted but doesn't show up in the
archive.  Please remove this guesswork to improve productivity.  Thank you.

Regards

Rolf

#780280#20
Date:
2021-02-26 15:17:25 UTC
From:
To:
Hey folks,

this issue still seems to exist, I just discovered that an upload I did
three months ago was never processed because I forgot to push my
extended key to Debian, which is a bit of a bummer.

Gr.

Matthijs