Please accept INSECURE GPG signature

Bug #914410 reported by Sylvestre Ledru
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
deb-o-matic
Fix Released
Medium
Unassigned

Bug Description

It would be nice if you could accept the attached commit (generated against the current main branch)
It allows the acceptation of the following output:

gpg: Signature made Tue 10 Jan 2012 07:05:09 PM CET using RSA key ID C8393B88
gpg: Good signature from "Sylvestre Ledru <email address hidden> (INSECURE!)"

Revision history for this message
Sylvestre Ledru (sylvestre) wrote :
Revision history for this message
Luca Falavigna (dktrkranz) wrote :

Thanks for the patch. I was considering its usefulness in current implementation. Could you provide some use cases for the new optional parameter?

Changed in debomatic:
importance: Undecided → Wishlist
Revision history for this message
Sylvestre Ledru (sylvestre) wrote :

Sure. When you are creating a GPG key without any passphrase, it shows this:
Good signature from "Sylvestre Ledru <email address hidden> (INSECURE!)"
(output which is not detected by debomatic)

Revision history for this message
Luca Falavigna (dktrkranz) wrote :

Ah, good point!

I don't think the extra noise at the end of the email is relevant, though. Regex could be transformed this way:
'Good signature from "(.*) <(.*)>.*"'

Changed in debomatic:
status: New → Triaged
importance: Wishlist → Medium
milestone: none → 0.10
Revision history for this message
Luca Falavigna (dktrkranz) wrote :
Changed in debomatic:
status: Triaged → Fix Committed
Revision history for this message
Luca Falavigna (dktrkranz) wrote :

Fixed in 0.10

Changed in debomatic:
milestone: 0.10 → none
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.