- Package:
- distro-info-data
- Source:
- distro-info-data
- Submitter:
- Johannes Schauer Marin Rodrigues
- Date:
- 2023-01-19 22:42:03 UTC
- Severity:
- normal
Hi, please consider storing a mapping from distro to keyring in /usr/share/keyring. Currently there is no reliable way to retrieve the authoritative keyring for a given distro name. Even when limiting oneself to only Debian, it is not obvious for which suites one needs /usr/share/keyrings/debian-archive-keyring.gpg and for which one needs /usr/share/keyrings/debian-archive-removed-keys.gpg. Thanks! cheers, josch
Hi, I am not sure whether distro-info-data is the right place for it. Are there rules when keys move from debian-archive-keyring.gpg to debian- archive-removed-keys.gpg? Shouldn't that information better be shipped by debian-archive-keyring? Who would be the consumers? How would that information be used?
Can someone from the release team answer how this works? Thanks, Stefano
Hi, Keys move to the removed keyring when they are no longer needed for bootstrapping supported or LTS releases (currently, stretch onwards). That's why there are typically three or four current keys depending on the phase of the release cycle.