repository is not signed

Bug #312681 reported by Kamil Páral
260
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Shutter
Fix Released
Medium
Mario Kemper (Romario)

Bug Description

GScrot repository is not signed with a PGP key. If it is, there is no information about it at:
https://launchpad.net/~gscrot/+archive
nor at:
https://answers.launchpad.net/gscrot/+faq/275

The download page should mention which key is used to sign the packages and how to add them to the system.

Every time there is an upgrade to GScrot, the package managers warns the user that GScrot is an unsigned and therefore potentially dangerous package. It is true, someone may hack into your repository and replace the packages with his own. If you want to ensure people's trust, you have to sign your package. It is absolutely necessary for large-spread packages like GScrot.

Please sign your repository and give us information about that on the download page. Thank you.

Revision history for this message
Rene Hennig (shifty) wrote : Re: [Bug 312681] [NEW] repository is not signed

This is a global bug by Launchpad - not from GScrot.
sorry!

Greets - shifty

Kamil Páral schrieb:
> *** This bug is a security vulnerability ***
>
> Public security bug reported:
>
> GScrot repository is not signed with a PGP key. If it is, there is no information about it at:
> https://launchpad.net/~gscrot/+archive
> nor at:
> https://answers.launchpad.net/gscrot/+faq/275
>
> The download page should mention which key is used to sign the packages
> and how to add them to the system.
>
> Every time there is an upgrade to GScrot, the package managers warns the
> user that GScrot is an unsigned and therefore potentially dangerous
> package. It is true, someone may hack into your repository and replace
> the packages with his own. If you want to ensure people's trust, you
> have to sign your package. It is absolutely necessary for large-spread
> packages like GScrot.
>
> Please sign your repository and give us information about that on the
> download page. Thank you.
>
> ** Affects: gscrot
> Importance: Undecided
> Status: New
>
> ** Visibility changed to: Public
>

Revision history for this message
Kamil Páral (kamil.paral) wrote :

What do you mean? Launchpad does not allow to sign its repositories? Can you post a link to the relevant bug?

Revision history for this message
Rene Hennig (shifty) wrote : Re: [Bug 312681] Re: repository is not signed

https://bugs.launchpad.net/soyuz/+bug/125103

It's not a bug fix, but a bad workaround ...

Revision history for this message
Mario Kemper (Romario) (mario-kemper) wrote :

Hello Kamil,

here are some more information about this topic:

http://brainstorm.ubuntu.com/idea/11810/

There seems to be a solution available in the near future as described here:
http://news.launchpad.net/general/preparing-for-signed-ppas

I'll sign the repository as soon as it is available. Thanks.

Greetings
Mario

Revision history for this message
Kamil Páral (kamil.paral) wrote :

Didn't know this. Thanks for the info.

Revision history for this message
Mario Kemper (Romario) (mario-kemper) wrote :

I'll keep this one open. Just as a reminder...

Changed in gscrot:
assignee: nobody → mario-kemper
importance: Undecided → Medium
status: New → Confirmed
Changed in gscrot:
status: Confirmed → In Progress
Revision history for this message
Mario Kemper (Romario) (mario-kemper) wrote :

repos at launchpad are signed now. next packages (shutter 0.70) will be signed.

Changed in shutter:
milestone: none → 0.70
Changed in shutter:
status: In Progress → Fix Released
Revision history for this message
Mario Kemper (Romario) (mario-kemper) wrote :

This one is generally fixed but please don't close this bug until new shutter packages are available (we are currently working on this).

Changed in shutter:
status: Fix Released → In Progress
Revision history for this message
Vadim Peretokin (vperetokin) wrote :
Changed in shutter:
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.