On Tue, Feb 19, 2013 at 09:04:47PM +0600, Andrey Rahmatullin wrote: > On Tue, Feb 19, 2013 at 09:47:13PM +0900, Osamu Aoki wrote: > > "Signing with pbuilder" or "signing later" ... both are fine. > > > > Especially building package on foreign machines require "sign later" to > > keep your GPG key secure on your machine. > Of course. Please read my email again. ... > Both strategies should be mentioned as rwo strategies. Now maint-guide > tells users to do both things each time and even directly states a wrong > thing (that after configuring pbuilder to sign packages they are still not > signed).
Now I have... |configuring ~/.pbuilderrc or /etc/pbuilderrc to include the followsing. ... |The newly built packages without the GPG signatures will be located in |/var/cache/pbuilder/result/ with non-root ownership. | |The GPG signatures on the .dsc file and the .changes file can be |generated as ... I see what you mean. I think I must have updated autosign thing without updating these together. I see typo too. |configuring ~/.pbuilderrc or /etc/pbuilderrc to include the |following. (optional) |<footnote>If you are building packages on a remote machine, it is bad |idea to have your GPG secret key there to sign your |packages.</footnote> ... |The newly built packages will be located in /var/cache/pbuilder/result/ |with non-root ownership. | |If you have chosen not to generate the GPG signatures on the .dsc file |and the .changes file automatically on the build machine, these files |can be moved to a secure system and the GPG signatures can be generated |later as Osamu -- To UNSUBSCRIBE, email to [email protected] with a subject of "unsubscribe". Trouble? Contact [email protected]

