Re: [bug-gsrc] Checking signatures on source tarballs

2015-10-13 Thread Ludovic Courtès
Brandon Invergo skribis: > On Mon, 2015-10-12 at 23:34 +0200, Ludovic Courtès wrote: > >> We would need the help and support of someone from the GNU Advisory >> Committee, I guess… >> >> :-) > > OK I think I know just the guy for the job. :) > > I'll start the discussion.  Feel free to ping me t

Re: [bug-gsrc] Checking signatures on source tarballs

2015-10-12 Thread Brandon Invergo
On Mon, 2015-10-12 at 23:34 +0200, Ludovic Courtès wrote: > We would need the help and support of someone from the GNU Advisory > Committee, I guess… > > :-) OK I think I know just the guy for the job. :) I'll start the discussion.  Feel free to ping me to check on the progress! -brandon sig

Re: [bug-gsrc] Checking signatures on source tarballs

2015-10-12 Thread Ludovic Courtès
Brandon Invergo skribis: > On Mon, 2015-10-12 at 18:38 +0200, Ludovic Courtès wrote: > >> However, this package → keys mapping necessarily exists somewhere.  I >> think we should ask the FSF to publish it and provide a way to >> authenticate it. >> >> WDYT? > > If they would be willing to publis

Re: [bug-gsrc] Checking signatures on source tarballs

2015-10-12 Thread Brandon Invergo
On Mon, 2015-10-12 at 18:38 +0200, Ludovic Courtès wrote: > However, this package → keys mapping necessarily exists somewhere.  I > think we should ask the FSF to publish it and provide a way to > authenticate it. > > WDYT? If they would be willing to publish it, I think it would be a very good

Re: [bug-gsrc] Checking signatures on source tarballs

2015-10-12 Thread Ludovic Courtès
Brandon Invergo skribis: > On Mon, 2015-10-12 at 09:37 +0100, Brandon Invergo wrote: > >> I could swear that previously a keyring of the GNU maintainers was >> made available by the FSF somewhere but I cannot find it. > > http://ftp.gnu.org/gnu/gnu-keyring.gpg The main issue is that this file is

Re: [bug-gsrc] Checking signatures on source tarballs

2015-10-12 Thread Brandon Invergo
On Mon, 2015-10-12 at 09:37 +0100, Brandon Invergo wrote: > I could swear that previously a keyring of the GNU maintainers was > made available by the FSF somewhere but I cannot find it. http://ftp.gnu.org/gnu/gnu-keyring.gpg Of course, this doesn't help for those GNU packages that are not made