Hi Laura,

05.08.2021 13:01, Laura Smith wrote:
> Hi
> 
> Any ideas where change suggestions for docs should be submitted ? 
> Specifically this page: http://nginx.org/en/linux_packages.html#Debian

Here is fine.

> The instructions presented are not inline with Debian best-practices.
> 
> As per https://wiki.debian.org/DebianRepository/UseThirdParty:
> "The key MUST be downloaded over a secure mechanism like HTTPS to a location 
> only writable by root, which SHOULD be /usr/share/keyrings. The key MUST NOT 
> be placed in /etc/apt/trusted.gpg.d or loaded by apt-key add. A sources.list 
> entry SHOULD have the signed-by option set. The signed-by entry MUST point to 
> a file, and not a fingerprint."

Yeah, I think it makes sense to rework it.  I'll prepare the patches -
thanks for the notification!

Relevant reading:

https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=861695
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=877012

Have a good day,

-- 
Konstantin Pavlov
https://www.nginx.com/
_______________________________________________
nginx mailing list
nginx@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx

Reply via email to