Package: ui-auto
Version: 1.2.9
Severity: wishlist
Control: affects -1 devscripts

Hi there--

the debrsign workflow isn't a particularly safe one (see discussion on
https://bugs.debian.org/855282 and https://bugs.debian.org/855320).

ui-auto should not encourage its use, and should probably either
explicitly deprecate or just drop support for the debrsign option.

Additionally, ui-auto-rsign seems to encourage the same dubious
workflow of making ssh connections from untrusted machines to trusted
machines.  It should probably be deprecated or removed as well.

Thanks for maintaining ui-auto for debian!

Regards,

        --dkg

-- System Information:
Debian Release: 9.0
  APT prefers testing-debug
  APT policy: (500, 'testing-debug'), (500, 'testing'), (200, 
'unstable-debug'), (200, 'unstable'), (1, 'experimental-debug'), (1, 
'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.9.0-1-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Reply via email to