Comment 16 for bug 1016643

Revision history for this message
dkg (dkg0) wrote :

I'm glad to see you rejecting the short keyid.

If you're doing this work to make the apt-key fetching possibilities cryptographically sound, please rely only on full OpenPGPv4 fingerprints, not on the long keyid. And ensure that the received key is an OpenPGP v4 key, since v3 fingerprints are themselves spoofable.

Thanks!