Re: cygport and gpg

2008-12-06 Thread Ken Brown
On 12/6/2008 12:19 PM, Brian Dessent wrote: It appears that in recent versions (0.9.1 and on) of cygport, failure to verify has been made informational and not fatal. But trunk versions of cygport are for cygwin 1.7 only so it looks like 1.5 will only ever see 0.4.x. Anyway, it's just a script.

Re: cygport and gpg

2008-12-06 Thread Brian Dessent
Ken Brown wrote: > I don't use gpg, but a look at the documentation suggests that I'm > supposed to import a public key. Should the key have been included with > the source package? I didn't see it there. No, keys are available from keyservers. You ought to be able to import it automatically w

cygport and gpg

2008-12-06 Thread Ken Brown
I'm trying to rebuild a cygwin package in order to diagnose some problems with it, but cygport fails because gpg can't verify the signature: gpg: WARNING: using insecure memory! gpg: please see http://www.gnupg.org/faq.html for more information gpg: Signature made Tue Feb 27 17:48:23 2007 EST us