- Package:
- ftp.debian.org
- Source:
- ftp.debian.org
- Submitter:
- Ansgar Burchardt
- Date:
- 2021-02-26 15:57:02 UTC
- Severity:
- wishlist
It would be nice if dak would generate rejection mails for uploads that have a valid signature, but where the signature is expired or from an expired key. daklib/gpg.py already has some support for differentiating between expired and invalid signatures, but some bits are still missing. Ansgar
Ansgar Burchardt: It would not only be nice, it would help not being trapped in very silly situation: files uploaded with a valid signature but with an expired key are not removed from the queue. That means teammates are unable to sponsor the upload while waiting for the keyring to be updated. It's not possible to remove them using dcut either as the key will still be expired… I would be grateful if you could properly REJECT uploads for such cases. Thanks,
Hello! Currently, the uploader of a package using an expired key is left guessing as to why the package was accepted but doesn't show up in the archive. Please remove this guesswork to improve productivity. Thank you. Regards Rolf
Hey folks, this issue still seems to exist, I just discovered that an upload I did three months ago was never processed because I forgot to push my extended key to Debian, which is a bit of a bummer. Gr. Matthijs