Please SRU archive keyrings to older releases

Bug #1752656 reported by Nish Aravamudan
10
This bug affects 1 person
Affects Status Importance Assigned to Milestone
debian-archive-keyring (Ubuntu)
Won't Fix
Undecided
Unassigned
ubuntu-keyring (Ubuntu)
Won't Fix
Undecided
Unassigned

Bug Description

While not necessarily a critical issue for the Ubuntu keyrings, as Debian uses newer keys periodically, it becomes impossible with the default keyrings to verify the latest Debian archive files.

It seems reasonable to ensure the keyring contents in all releases are the same, as the latest release is reflecting the latest archives.

Related: bug 1801725

Robie Basak (racb)
description: updated
Revision history for this message
Colin Watson (cjwatson) wrote :

Note that SRUing debian-archive-keyring to xenial and earlier is hard, because its keyring generation code relies on gpg features that were added after bionic, and avoiding those features would break reproducibility of the generated keyring files and invalidate the signatures by Debian release team members. If we need to do this it's possible the only sensible option would be to smash in the generated files.

Revision history for this message
Dimitri John Ledkov (xnox) wrote :

SRU of debian keyring is also somehow counter productive. Most likely usecase is to debootstrap unstable chroot. And for that to be done correctly, often enough most recent debootstrap from debian is required as otherwise the debootstrap might not complete, or complete incorrectly (see all the recent usrmerge changes and flip-flops).

Similarly in Ubuntu keyring we have similar issue with debootstrap. However we are trying to maintain as large overlap window as possible.

But it is impractical to SRU all keyrings ever, to all releases ever. Thus this item is won't fix.

Changed in ubuntu-keyring (Ubuntu):
status: New → Won't Fix
Changed in debian-archive-keyring (Ubuntu):
status: New → Won't Fix
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.