ubuntu-keyring migrate to fragment files

Bug #1624408 reported by Dimitri John Ledkov
260
This bug affects 1 person
Affects Status Importance Assigned to Milestone
ubuntu-keyring (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

Instead of shipping a single keyring with 4 keys, ship each key individually in trusted.gpg.d and do not call apt-key update at all.

Remove keys from /etc/apt/trusted.gpg

This is similar to changes done in debian-archive-keyring 2012.1 upload.

Revision history for this message
Dimitri John Ledkov (xnox) wrote :
Revision history for this message
Dimitri John Ledkov (xnox) wrote :

ubuntu-keyring (2016.09.19) yakkety; urgency=medium

  * Ship each active key in a separate keyring in /etc/apt/trusted.gpg.d/
    as conffiles for simpler usage of apt-secure(8).
  * Remove all active keys from /etc/apt/trusted.gpg as they are shipped
    now as fragment files.
  * Depend on gpgv and only recommend gnupg.
  * Stop calling apt-key update LP: #1619444
  * Generate SHA512SUMS.txt.asc file, signed by me, and verified against
    debian-keyring at build time as a weak consistency check.

 -- Dimitri John Ledkov <email address hidden> Fri, 16 Sep 2016 14:36:10 +0100

Changed in ubuntu-keyring (Ubuntu):
status: New → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.