On Tue, Feb 19, 2013 at 09:47:13PM +0900, Osamu Aoki wrote: > "Signing with pbuilder" or "signing later" ... both are fine. > > Especially building package on foreign machines require "sign later" to > keep your GPG key secure on your machine. Of course. Please read my email again.
> I recognize there are some possibility for improvement around here but > no error of mentioning both strategy. Both strategies should be mentioned as rwo strategies. Now maint-guide tells users to do both things each time and even directly states a wrong thing (that after configuring pbuilder to sign packages they are still not signed). -- WBR, wRAR
signature.asc
Description: Digital signature

