GNU bug report logs - #17625
details of package signing mechanism

Previous Next

Package: emacs;

Reported by: Eric Abrahamsen <eric <at> ericabrahamsen.net>

Date: Thu, 29 May 2014 03:12:01 UTC

Severity: important

Tags: security

Found in version 24.4.50

Done: Stefan Monnier <monnier <at> iro.umontreal.ca>

Bug is archived. No further changes may be made.

Full log


Message #8 received at 17625 <at> debbugs.gnu.org (full text, mbox):

From: Glenn Morris <rgm <at> gnu.org>
To: Eric Abrahamsen <eric <at> ericabrahamsen.net>
Cc: 17625 <at> debbugs.gnu.org
Subject: Re: bug#17625: 24.4.50;
 All installed packages marked "unsigned", no archive listed
Date: Fri, 30 May 2014 01:14:15 -0400
Eric Abrahamsen wrote:

> The command `list-packages' then gives me a *Package* buffer in which
> all installed packages are marked as "unsigned", in a bright red face,
> and the "archive" column is empty. Getting info on any of these
> installed packages shows a *Help* screen where the "Archive" heading
> reads n/a, but "Version" obviously matches on of the versions mentioned
> in "Other versions". I've attached a screenshot which should make all of
> this obvious. Apparently it's not supposed to be like this.


Do any package archives actually sign their packages?

The mechanism by which they are supposed to do so seems completely
undocumented (it's not even mentioned in NEWS), so I have no idea how they
are expected to do so.




This bug report was last modified 10 years and 236 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.