Andreas Barth <[EMAIL PROTECTED]> writes: > - secure apt > secure apt is now part of testing. However, we need to do something for key > management etc - so some small issues need to be resolved.
>From a usability standpoint I find this the largest problem in debian today. Finding the right key and getting it added to apt has been a problem for so many users already and those are only the etch/sid users. I have two suggestions on this subject: 1) Create debian/dists/<suite>/Release.key I asked ftp-master before to place the respective key there but so far nothing has happened. The key should be placed in a common place for any apt-get-able archive, be that debian, ubuntu, security, backports or any of the others. Placing the key next to the Release and Release.gpg file is the most logical place for both software and humans to find it. Having Release.key be a keyring (instead of a single key) should allow it to include revokations in case a key gets compromised, right? 2) 'apt-* update' should fetch Release.key Keys should be fetchable directly from a debian archive, be that a cd, file, ftp or http url in sources.list. I would prefer apt-get update to do that when needed but if someone insists then apt-key update can do it and apt-get can tell users about that for missing keys. For obvious reasons a fetched key(ring) should not be silently added to the apt keyring but checked first. That means checking all signatures, showing the user the result [e.g. New key <id>: X signatures check, Y signatures unknown, Z signatures failed. Accept/Reject/Ignore/Details?] and let the user decide what to do about it. A user should not have to first research about gpg and apt-key at length to find the correct syntax and definetly shouldn't be at loss as to where to find the key as it is now. Having the key in the debian-keyring package was a nice idea but ultimatly useless. Sarge users can't fetch the new etch keyring package because the signature doesn't match and the signature doesn't match because the sarge keyring doesn't have the key. Fun fun fun. MfG Goswin -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]