On Thu, 31 Oct 2013, adrelanos wrote: > But what could you do with the revocation certificate? > > Only manually spread the news and ask users to obtain the revocation > certificate?
We would widely publish that information, that's a given. But it is not the only way to publish the revocation certificate and the replacement keys. > Or will the apt on Debian user's machines somehow learn about that > revocation certificate? If so, how does that procedure work? Where is it > configured? I believe we'd deploy a security update of the "debian-archive-keyring" package, with the updated key material and revocation certificates. There are backup keys to allow for key rollover. Now, this does NOT address all scenarios. It is not a perfect solution. For a more precise answer, please ask the debian-admin ML. -- "One disk to rule them all, One disk to find them. One disk to bring them all and in the darkness grind them. In the Land of Redmond where the shadows lie." -- The Silicon Valley Tarot Henrique Holschuh -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: http://lists.debian.org/20131101171006.ga1...@khazad-dum.debian.net