Lucid/Maverick package doesn't contain new Sid/Squeeze keys

Bug #722521 reported by Bilal Akhtar on 2011-02-21
14
This bug affects 2 people
Affects Status Importance Assigned to Milestone
debian-archive-keyring (Ubuntu)
Undecided
Unassigned
Lucid
Medium
Bilal Akhtar
Maverick
Medium
Bilal Akhtar

Bug Description

Binary package hint: debian-archive-keyring

The Lucid and Maverick package of d-a-k doesn't include the new Sid and Squeeze keys being used for signing on the Debian archives.

The major symptom of this bug is that creating a pbuilder Debian chroot fails with an Authentication failure since the required keys aren't in the keyring.

The fixed version of the package has been uploaded to maverick-proposed as well as lucid-proposed. The package is actually a full package backport from Natty. This had to be done because the Lucid/Maverick package had pre-created .gpg trustsigs which could be modified only by a member of the Debian Release team. Moreover, every part of the package was digitally signed and the signatures were tested on every build. All this made the backport from Natty the only solution.

Regressions aren't likely because:
1) The bug fix is small
2) Other structural changes in package are highly proven

TEST CASE: 1) Install ubuntu-dev-tools, and run the command: pbuilder-dist sid create
2) The above command should fail, with a message saying that the release file was signed with an unknown key.
3) Install the -proposed version of debian-archive-keyring
4) Run pbuilder-dist sid create (No need to wait for the command to finish, if it says 'I: Valid signature key' you can press <Control>+C and stop pbuilder-dist). If you get the 'I: Valid signature key' message, then it means you just successfully verified this SRU.

Changed in debian-archive-keyring (Ubuntu):
status: New → Fix Released
Changed in debian-archive-keyring (Ubuntu Lucid):
assignee: nobody → Bilal Akhtar (bilalakhtar)
importance: Undecided → Medium
milestone: none → lucid-updates
status: New → In Progress
Changed in debian-archive-keyring (Ubuntu Maverick):
assignee: nobody → Bilal Akhtar (bilalakhtar)
importance: Undecided → Medium
milestone: none → maverick-updates
status: New → In Progress
description: updated
Changed in debian-archive-keyring (Ubuntu Maverick):
status: In Progress → Fix Committed
Changed in debian-archive-keyring (Ubuntu Lucid):
status: In Progress → Fix Committed
description: updated

Accepted debian-archive-keyring into maverick-proposed, the package will build now and be available in a few hours. Please test and give feedback here. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation how to enable and use -proposed. Thank you in advance!

tags: added: verification-needed
Martin Pitt (pitti) wrote :

Accepted debian-archive-keyring into lucid-proposed, the package will build now and be available in a few hours. Please test and give feedback here. See https://wiki.ubuntu.com/Testing/EnableProposed for documentation how to enable and use -proposed. Thank you in advance!

Bilal Akhtar (bilalakhtar) wrote :

I started an Amazon EC2 instance running Ubuntu Maverick with the latest updates and I also installed debian-archive-keyring from maverick-proposed. The package did its job as it is supposed to do and pbuilder succeeded in building sid/squeeze chroots, unlike the latest package in the release pocket which doesn't contain the new keys and makes pbuilder fail at sid chroots.

Hence I successfully verified this package on maverick.

tags: added: verification-done
removed: verification-needed
Martin Pitt (pitti) wrote :

Setting back to v-needed for lucid update.

tags: added: verification-done-maverick verification-needed
removed: verification-done
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package debian-archive-keyring - 2010.08.28~maverick

---------------
debian-archive-keyring (2010.08.28~maverick) maverick-proposed; urgency=low

  * Backport natty package containing newly-released squeeze and sid keys.
    (LP: #722521)
  * Makefile: Create homedir before running GPG commands to workaround
    FTBFS due to GPG bug in Maverick.
 -- Bilal Akhtar <email address hidden> Mon, 21 Feb 2011 13:23:23 +0300

Changed in debian-archive-keyring (Ubuntu Maverick):
status: Fix Committed → Fix Released
Pedro Villavicencio (pedro) wrote :

I've verified the proposed package for lucid and can confirm that it fixes the issue there as well, marking this as verification-done, thanks all.

tags: added: verification-done
removed: verification-needed
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package debian-archive-keyring - 2010.08.28~lucid

---------------
debian-archive-keyring (2010.08.28~lucid) lucid-proposed; urgency=low

  * Backport natty package containing newly-released squeeze and sid keys.
    (LP: #722521)
  * Makefile: Create homedir before running GPG commands to workaround
    FTBFS due to GPG bug in Lucid.
 -- Bilal Akhtar <email address hidden> Mon, 21 Feb 2011 14:49:34 +0300

Changed in debian-archive-keyring (Ubuntu Lucid):
status: Fix Committed → Fix Released
tags: added: testcase
To post a comment you must log in.
This report contains Public information  Edit
Everyone can see this information.

Other bug subscribers