Bug#338889: Overzealously prefers signed packages to identical unsigned ones

2006-12-12 Thread Goswin von Brederlow
Santiago Vila <[EMAIL PROTECTED]> writes: > On Wed, 23 Nov 2005, Goswin von Brederlow wrote: > >> But in the general case it would be nice if apt-get would get the >> file/size/md5sum from a trusted Packages file and then fetch the deb >> from an untrusted source if it matches. > > On Wed, 23 Nov

Bug#338889: Overzealously prefers signed packages to identical unsigned ones

2006-12-12 Thread Santiago Vila
On Wed, 23 Nov 2005, Goswin von Brederlow wrote: > But in the general case it would be nice if apt-get would get the > file/size/md5sum from a trusted Packages file and then fetch the deb > from an untrusted source if it matches. On Wed, 23 Nov 2005, Andras Korn wrote: > [...] if two packages ha

Bug#338889: Overzealously prefers signed packages to identical unsigned ones

2005-11-23 Thread Andras Korn
On Wed, Nov 23, 2005 at 04:47:02PM +0100, Michael Vogt wrote: Hi, > > I have a local package repository that is pieced together from many > > different sources. I don't have a signed Release file (is there an easy way > > to generate one automatically?); I only generate my own Packages file. > >

Bug#338889: Overzealously prefers signed packages to identical unsigned ones

2005-11-23 Thread Goswin von Brederlow
Michael Vogt <[EMAIL PROTECTED]> writes: > On Sun, Nov 13, 2005 at 04:37:15PM +0100, Andras Korn wrote: >> Package: apt >> Version: 0.6.42.3 >> Severity: normal > > Thanks for your bugreport. > >> I have a local package repository that is pieced together from many >> different sources. I don't h

Bug#338889: Overzealously prefers signed packages to identical unsigned ones

2005-11-23 Thread Michael Vogt
On Sun, Nov 13, 2005 at 04:37:15PM +0100, Andras Korn wrote: > Package: apt > Version: 0.6.42.3 > Severity: normal Thanks for your bugreport. > I have a local package repository that is pieced together from many > different sources. I don't have a signed Release file (is there an easy way > to g

Bug#338889: Overzealously prefers signed packages to identical unsigned ones

2005-11-13 Thread Andras Korn
Package: apt Version: 0.6.42.3 Severity: normal Hi, I have a local package repository that is pieced together from many different sources. I don't have a signed Release file (is there an easy way to generate one automatically?); I only generate my own Packages file. The patch to this local repos