GNU bug report logs - #17625
details of package signing mechanism

Previous Next

Package: emacs;

Reported by: Eric Abrahamsen <eric <at> ericabrahamsen.net>

Date: Thu, 29 May 2014 03:12:01 UTC

Severity: important

Tags: security

Found in version 24.4.50

Done: Stefan Monnier <monnier <at> iro.umontreal.ca>

Bug is archived. No further changes may be made.

Full log


View this message in rfc822 format

From: Eli Zaretskii <eliz <at> gnu.org>
To: Ted Zlatanov <tzz <at> lifelogs.com>
Cc: monnier <at> iro.umontreal.ca, 17625 <at> debbugs.gnu.org
Subject: bug#17625: 24.4.50; All installed packages marked "unsigned", no archive listed
Date: Tue, 30 Sep 2014 17:24:19 +0300
> From: Ted Zlatanov <tzz <at> lifelogs.com>
> Date: Tue, 30 Sep 2014 07:02:51 -0400
> Cc: 17625 <at> debbugs.gnu.org
> 
> On Mon, 29 Sep 2014 23:55:00 -0400 Stefan Monnier <monnier <at> iro.umontreal.ca> wrote: 
> 
> >> @c Uncomment this if it becomes true.
> >> @ignore
> >> The public key for the GNU package archive is distributed with Emacs,
> >> in the @file{etc/package-keyring.gpg}.  Emacs uses it automatically.
> >> @end ignore
> >> The ELPA maintainer public key .gpg file is needed. Right now I can't
> >> find it so I can't actually verify any packages. Am I missing something?
> 
> SM> It's in the file described in the (commented out) doc you cited above.
> SM> You are tracking emacs-24 to help us with the pretest, right?
> 
> I am, but looked in the trunk for this file. I didn't expect you'd put
> the keyring only in the emacs-24 branch.  Why keep it out of trunk?
> Users there won't know to look in emacs-24.

Everything in the emacs-24 branch gets merged to the trunk shortly.




This bug report was last modified 10 years and 236 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.