Bug#821051: [PATCH v3 3/3] dak.conf: add packages that trigger byhand-code-sign

2017-01-04 Thread Helen Koike
On 2016-12-12 07:35 PM, Joerg Jaspert wrote: On 14519 March 1977, Ben Hutchings wrote: We offer the archives, including security, by rsync too. And that should stay. Mirrors of security do exist, for good reasons.[1] Why does it need to be in the archive? [...] I don't know of any other way

Bug#821051: [PATCH v3 3/3] dak.conf: add packages that trigger byhand-code-sign

2016-12-12 Thread Joerg Jaspert
On 14519 March 1977, Ben Hutchings wrote: >> We offer the archives, including security, by rsync too. >> And that should stay. Mirrors of security do exist, for good >> reasons.[1] >> Why does it need to be in the archive? > [...] > I don't know of any other way of getting files back out of dak.

Bug#821051: [PATCH v3 3/3] dak.conf: add packages that trigger byhand-code-sign

2016-12-12 Thread Ben Hutchings
On Mon, 2016-12-12 at 22:24 +0100, Joerg Jaspert wrote: > On 14519 March 1977, Ben Hutchings wrote: > > > The first is acceptable, the latter is not, for hopefully obvious > > > reasons. > > > > I meant the latter.  Your reason for objecting is not obvious to > > me.  I > > understand that this

Bug#821051: [PATCH v3 3/3] dak.conf: add packages that trigger byhand-code-sign

2016-12-12 Thread Joerg Jaspert
On 14519 March 1977, Ben Hutchings wrote: >> The first is acceptable, the latter is not, for hopefully obvious reasons. > I meant the latter. Your reason for objecting is not obvious to me. I > understand that this can't be done for the main archive and all its > mirrors, which is fine - this is

Bug#821051: [PATCH v3 3/3] dak.conf: add packages that trigger byhand-code-sign

2016-12-12 Thread Ben Hutchings
On Mon, 2016-12-12 at 19:30 +0100, Joerg Jaspert wrote: > On 14506 March 1977, Ben Hutchings wrote: > > > 1. Directory listing is disabled for the directory containing > >    signature tarballs. > > There is a load of mails and irc discussions mixing together, so one > question here: Is that

Bug#821051: [PATCH v3 3/3] dak.conf: add packages that trigger byhand-code-sign

2016-12-12 Thread Joerg Jaspert
On 14506 March 1977, Ben Hutchings wrote: > 1. Directory listing is disabled for the directory containing >signature tarballs. There is a load of mails and irc discussions mixing together, so one question here: Is that supposed to be on some (restricted!) host somewhere with a limited apache

Bug#821051: [PATCH v3 3/3] dak.conf: add packages that trigger byhand-code-sign

2016-11-29 Thread Ben Hutchings
On Tue, 2016-11-29 at 12:23 -0200, Helen Koike wrote: > > On 2016-11-20 09:27 AM, Ben Hutchings wrote: > > On Wed, 2016-11-16 at 00:45 -0200, Helen Koike wrote: > > > Add linux, grub2 and fwupdate to publish their signatures by calling > > > byhand-code-sign as they are supposed to have a

Bug#821051: [PATCH v3 3/3] dak.conf: add packages that trigger byhand-code-sign

2016-11-29 Thread Helen Koike
On 2016-11-20 09:27 AM, Ben Hutchings wrote: On Wed, 2016-11-16 at 00:45 -0200, Helen Koike wrote: Add linux, grub2 and fwupdate to publish their signatures by calling byhand-code-sign as they are supposed to have a *-signed version NOTE: this bypass embargoed updates. The proposed solution

Bug#821051: [PATCH v3 3/3] dak.conf: add packages that trigger byhand-code-sign

2016-11-20 Thread Ben Hutchings
On Wed, 2016-11-16 at 00:45 -0200, Helen Koike wrote: > Add linux, grub2 and fwupdate to publish their signatures by calling > byhand-code-sign as they are supposed to have a *-signed version > > NOTE: this bypass embargoed updates. The proposed solution for this is by > making dak to publish the

Bug#821051: [PATCH v3 3/3] dak.conf: add packages that trigger byhand-code-sign

2016-11-15 Thread Helen Koike
Add linux, grub2 and fwupdate to publish their signatures by calling byhand-code-sign as they are supposed to have a *-signed version NOTE: this bypass embargoed updates. The proposed solution for this is by making dak to publish the *-signed packages automatically, this will be implemented in