Package: ftp.debian.org
Severity: normal

Hi,

A few days ago I set the following option into my gpg.conf:

  ,---
  sig-keyserver-url 
https://www.hadrons.org/~guillem/guillem-4F3E74F436050C10F5696574B972BF3EA4AE57A3.asc
  `---

Yesterday I uploaded a couple of packages (pci.ids and inetutils) which
got processes by the archive, but for which I never got REJECTED nor
ACCEPTED mail.

Today I reuploaded pci.ids a couple of times, then realized it might
be the new GnuPG setting. The signature verified like this:

  ,---
  $ gpg --verify pci.ids_0.0~2022.07.05-1_amd64.changes
  gpg: Signature made Fri Jul  8 22:16:56 2022 CEST
  gpg:                using RSA key 4F3E74F436050C10F5696574B972BF3EA4AE57A3
  gpg: Good signature from "Guillem Jover <guil...@hadrons.org>" [ultimate]
  gpg:                 aka "Guillem Jover <guil...@debian.org>" [ultimate]
  gpg: Preferred keyserver: 
https://www.hadrons.org/~guillem/guillem-4F3E74F436050C10F5696574B972BF3EA4AE57A3.asc
  Primary key fingerprint: 4F3E 74F4 3605 0C10 F569  6574 B972 BF3E A4AE 57A3
  `---

I disabled the setting, resigned and reuploaded, and then both
packages got ACCEPTED. So I assume there's something in DAK that is
unable to parse additional information in the signatures, which is
rather surprising.

Thanks,
Guillem

Reply via email to