Bug#1110172: Keys in a user's trustedkeys.gpg keyring are ignored when extracting a source package
Martin-Éric Racine <[email protected]> Fri, 19 Dec 2025 10:07:11 +0200
| Newsgroups | gmane.linux.debian.devel.dpkg.bugs |
|---|---|
| Message-ID | <CAPZXPQcV3tWBCQoHCit02qfcERG8iD+vmUUG2jNsRFQb=hCOSg__7330.02118520147$1766132383$gmane$org@mail.gmail.com> |
pe 19.12.2025 klo 0.39 Guillem Jover ([email protected]) kirjoitti: > On Wed, 2025-12-17 at 12:07:55 +0200, Martin-Éric Racine wrote: > > However, no longer checking the user's own keyring really is a > > regression. This needs to be fixed. IMHO, a good implementation > > would be to first check the global keyrings (which it already does) > > then check the user's own keyring as a last resort (which was removed > > for no good reason). > > I explained the reasons in my first reply to this report. > > The GnuPG specific trustedkeys.kbx or trustedkeys.gpg keyrings are > being deprecated, as they are implementation specific, potentially > using a non-standard keyring format not understood by anything else. Is there a standards-based keyring format that would replace it? Heck, at this rate, Debian might as well stop shipping GnuPG altogether. Martin-Éric