Comment 3 for bug 638384

Revision history for this message
Steve Langasek (vorlon) wrote : Re: [Bug 638384] Re: hwpack-install asks for confirmation of not authenticated packages

On Wed, Sep 15, 2010 at 03:24:59PM -0000, Guilherme Salgado wrote:
> This happens for the debs that are included in the hwpack but I suspect
> it's because the hwpack doesn't include the gpg key used to sign the
> Packages file in it, or else it'd have been added to the apt keyring by
> linaro-hwpack-install.

Downloading unsigned hwpacks that contain a gpg for you to add to your apt
keyring is rather "security theater", though. Either the hwpacks themselves
should be signed and we should bypass the requirement for Packages signing
for the resulting local archive (similar to what's commonly done for CD
images), or the key used for Packages signing needs to be packaged and
included in the base images.

--
Steve Langasek Give me a lever long enough and a Free OS
Debian Developer to set it on, and I can move the world.
Ubuntu Developer http://www.debian.org/
<email address hidden> <email address hidden>