GNU bug report logs - #17625
details of package signing mechanism

Previous Next

Package: emacs;

Reported by: Eric Abrahamsen <eric <at> ericabrahamsen.net>

Date: Thu, 29 May 2014 03:12:01 UTC

Severity: important

Tags: security

Found in version 24.4.50

Done: Stefan Monnier <monnier <at> iro.umontreal.ca>

Bug is archived. No further changes may be made.

Full log


View this message in rfc822 format

From: Ted Zlatanov <tzz <at> lifelogs.com>
To: Daiki Ueno <ueno <at> gnu.org>
Cc: 17625 <at> debbugs.gnu.org
Subject: bug#17625: 24.4.50; All installed packages marked "unsigned", no archive listed
Date: Tue, 30 Sep 2014 07:06:59 -0400
On Tue, 30 Sep 2014 10:28:18 +0900 Daiki Ueno <ueno <at> gnu.org> wrote: 

DU> Ted Zlatanov <tzz <at> lifelogs.com> writes:
>> From the code it seems the EPG glue written by Daiki Ueno expects the
>> keyring to live in `(expand-file-name "gnupg" package-user-dir)` which
>> implies we have to provide a way, on startup, to populate that keyring
>> if it's missing. I don't see any docs or functions to do that. It's not
>> terribly complicated, just `gpg --homedir DIRNAME --import KEY` but it
>> would be convenient for users if we provide a wrapper.

DU> We already have it, and package-keyring.gpg is automatically imported on
DU> startup.  See package-import-keyring and package-refresh-contents (the
DU> caller).

I see it now, and thank you for pointing it out. The keyring file was
missing for me when testing from trunk so I didn't catch that, sorry.

Thanks
Ted




This bug report was last modified 10 years and 236 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.