#993590 distro-info-data: Store a mapping from distro to gpg keyring

#993590#5
Date:
2021-09-03 13:16:54 UTC
From:
To:
Hi,

please consider storing a mapping from distro to keyring in
/usr/share/keyring. Currently there is no reliable way to retrieve the
authoritative keyring for a given distro name. Even when limiting
oneself to only Debian, it is not obvious for which suites one needs
/usr/share/keyrings/debian-archive-keyring.gpg and for which one needs
/usr/share/keyrings/debian-archive-removed-keys.gpg.

Thanks!

cheers, josch

#993590#10
Date:
2023-01-16 17:25:22 UTC
From:
To:
Hi,

I am not sure whether distro-info-data is the right place for it. Are
there rules when keys move from debian-archive-keyring.gpg to debian-
archive-removed-keys.gpg? Shouldn't that information better be shipped
by debian-archive-keyring?

Who would be the consumers? How would that information be used?

#993590#15
Date:
2023-01-19 17:00:29 UTC
From:
To:
Can someone from the release team answer how this works?

Thanks,

Stefano

#993590#20
Date:
2023-01-19 22:18:00 UTC
From:
To:
Hi,

Keys move to the removed keyring when they are no longer needed for
bootstrapping supported or LTS releases (currently, stretch onwards).
That's why there are typically three or four current keys depending on the
phase of the release cycle.