Sven Ulland <[email protected]> (2014-02-04):
> Having an option to require a trust path would be good. It can be off
> by default to avoid compatibility issues and creeping security lax.
> 
> As it stands, there is no convenient way to require signature
> verification with debootstrap itself, so I'm currently working around
> it with an additional script before running debootstrap.

I've pushed two patches to that effect, feel free to give them a shot
and tell me whether that does the trick:
  https://anonscm.debian.org/cgit/d-i/debootstrap.git/commit/?id=be99f7b
  https://anonscm.debian.org/cgit/d-i/debootstrap.git/commit/?id=f961ecc

Mraw,
KiBi.

Attachment: signature.asc
Description: Digital signature

Reply via email to