< slangasek> asac: ah.  well, I would argue that relying on LP SSL to verify 
.dsc files is the wrong trust 
                   model

I think this has a point. And while using ca-certificates in recommends
is probably helpful, couldnt me also make dget just print a warning and
ignore certificates? Note that .dsc files are verified by gpg anyway.

** Changed in: devscripts (Ubuntu)
       Status: New => Incomplete

-- 
dget/dgetlp should have ca-certificates in their Recommends field.
https://bugs.launchpad.net/bugs/247157
You received this bug notification because you are a member of MOTU,
which is subscribed to ubuntu-dev-tools in ubuntu.

-- 
universe-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/universe-bugs

Reply via email to