On Tue, Feb 19, 2013 at 09:04:47PM +0600, Andrey Rahmatullin wrote:
> On Tue, Feb 19, 2013 at 09:47:13PM +0900, Osamu Aoki wrote:
> > "Signing with pbuilder" or "signing later" ... both are fine.
> > 
> > Especially building package on foreign machines require "sign later" to
> > keep your GPG key secure on your machine.
> Of course. Please read my email again.
...
> Both strategies should be mentioned as rwo strategies. Now maint-guide
> tells users to do both things each time and even directly states a wrong
> thing (that after configuring pbuilder to sign packages they are still not
> signed).

Now I have...

|configuring ~/.pbuilderrc or /etc/pbuilderrc to include the followsing.
...
|The newly built packages without the GPG signatures will be located in
|/var/cache/pbuilder/result/ with non-root ownership.
|
|The GPG signatures on the .dsc file and the .changes file can be
|generated as
...

I see what you mean.

I think I must have updated autosign thing without updating these
together.  I see typo too.

|configuring ~/.pbuilderrc or /etc/pbuilderrc to include the 
|following. (optional)
|<footnote>If you are building packages on a remote machine, it is bad
|idea to have your GPG secret key there to sign your
|packages.</footnote>
...
|The newly built packages will be located in /var/cache/pbuilder/result/
|with non-root ownership.
|
|If you have chosen not to generate the GPG signatures on the .dsc file
|and the .changes file automatically on the build machine, these files 
|can be moved to a secure system and the GPG signatures can be generated 
|later as

Osamu


-- 
To UNSUBSCRIBE, email to [email protected]
with a subject of "unsubscribe". Trouble? Contact [email protected]

Reply via email to