Opened 14 years ago
Last modified 12 years ago
#221 closed task
Put the apt repo signing key somewhere reasonable — at Initial Version
Reported by: | adehnert | Owned by: | |
---|---|---|---|
Priority: | major | Milestone: | |
Component: | internals | Keywords: | |
Cc: |
Description
At the moment, achernya has the apt repo signing key on his laptop. We should put it somewhere more useful.
See discussion 2011-09-09 on -c scripts -i apt.
- Stick it in the locker
- Stick it in the locker, encrypted to maintainer's keys
- Stick it on the hosts
- Stick it on the Fedora guests
- Stick it on some build VM or server
- Something else
- Have each maintainer store it themselves
(3) is a bit silly. Other than that, I think they were all vaguely acceptable. One concern is whether a signed repo with a leaked key is worse than an unsigned repo (if it isn't, then being insecure is vaguely okay). (4) should ideally avoid having a single un-backed-up VM that needs to not vanish, by storing the key elsewhere.
Note: See
TracTickets for help on using
tickets.