Package: dput
Version: 0.12
Severity: normal

When verifying a GnuPG-signed file, ‘dput’ can sometimes emit a confusing
error:

=====
[…]
Checking signature on .changes
gpg: ../build-area/foo_1.2_source.changes: Error checking signature from 
F9B46AAC84420C82: SignatureVerifyError: 0
Checking signature on .dsc
gpg: ../build-area/foo_1.2.dsc: Error checking signature from F9B46AAC84420C82: 
SignatureVerifyError: 0
[…]
=====

The program continues, but this message is misleading when the signature is
actually valid.

If there is no problem with the signature, no message like this should be
emitted; if there is a problem with the signature, the message should
clearly state what it is.

-- 
 \      “The history of Western science confirms the aphorism that the |
  `\     great menace to progress is not ignorance but the illusion of |
_o__)            knowledge.” —Daniel J. Boorstin, historian, 1914–2004 |
Ben Finney

Attachment: signature.asc
Description: PGP signature

Reply via email to