Bug#933185: fai-server: /etc/fai/apt/sources.list should not contain trusted=yes to skip GPG verification

2019-08-15 Thread Christian Seiler
Hi, (Sorry, overlooked your email.) Am 2019-08-12 21:31, schrieb Thomas Lange: I think we cannot fix it in this way. gpg --export 2BF8D9FE074BCDE4 may not work, if the key is not already downloaded and available for gpg. I also do not want to force to install the package debian-keyring on the

Bug#933185: fai-server: /etc/fai/apt/sources.list should not contain trusted=yes to skip GPG verification

2019-08-12 Thread Thomas Lange
I think we cannot fix it in this way. gpg --export 2BF8D9FE074BCDE4 may not work, if the key is not already downloaded and available for gpg. I also do not want to force to install the package debian-keyring on the fai server. And we should not create a file when calling fai-make-nfsroot under

Bug#933185: fai-server: /etc/fai/apt/sources.list should not contain trusted=yes to skip GPG verification

2019-07-27 Thread Christian Seiler
Package: fai-server Version: 5.8.4 Severity: grave Tags: security, buster Dear Maintainer, fai-server installs /etc/fai/apt/sources.list with the following entry by default: deb [trusted=yes] http://fai-project.org/download buster koeln This is problematic, as the [trusted=yes] part will tell