debian-keyring is a rather heavyweight Recommends for ubuntu-dev-tools, perhaps demote to Suggests?

Bug #1188036 reported by Max Bowsher
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
ubuntu-dev-tools (Ubuntu)
Won't Fix
Undecided
Unassigned

Bug Description

debian-keyring was promoted from a Suggests to a Recommends as a result of a user report in bug 717245.

However, either behaviours of tools have changed since then, or there was confusion between errors and warnings - if I use pull-debian-source without having debian-keyring installed on raring, the only downside is a couple of minor warning messages printed:

gpgv: Can't check signature: public key not found
dpkg-source: warning: failed to verify signature on ./squashfs-tools_4.2+20130409-1.dsc

but the package is unpacked successfully.

debian-keyring is a huge package (42MB .deb) compared to ubuntu-dev-tools (157K .deb), so I'd suggest that it be demoted to a Suggests again, given the only purpose is to enable an optional feature.

This is of course a somewhat a matter of opinion, so feel free to Won't Fix if you don't agree.

Revision history for this message
Stefano Rivera (stefanor) wrote :

Arguably cryptographic verification isn't an optional feature.

I'd be happy to lower this to Suggests, if we printed an explanation in pull-debian-source, when the keyring isn't available

Revision history for this message
Benjamin Drung (bdrung) wrote :

I prefer to have debian-keyring installed by default, because cryptographic verification is important IMO. Not doing cryptographic verification can cause a security issue, but Ubuntu should be secure by default. debian-keyring is just a recommendation. You can remove it if it is to heavyweight for you.

Revision history for this message
Dan Streetman (ddstreet) wrote :

as this is years old, closing as wontfix

Changed in ubuntu-dev-tools (Ubuntu):
status: New → Won't Fix
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.