Comment 3 for bug 1409117

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

apt-add-repository validates that the key that was downloaded is the right one before importing it, it doesn't blindly trust the key that gpg downloaded from the keyserver.

This is wishlist simply because it's security hardening. I will include it in the next gnupg security upload.