gpg key?
Using Ubuntu 8.04, during the update I get a warning "Not Authenticated" for the repos. Where is the gpg key?
20
people have this question
I have this question, too!
Tell me when someone answers.
The more people who ask this question, the more it gets noticed.
The more people who ask this question, the more it gets noticed.
Create a customer community for your own organization
Plans starting at $19/month
-
Inappropriate?We don't sign our packages, so there is no gpg key.
2 people say
this answers the question
-
I have the same problem, but It won't install the program without a gpg key, what to do then? I click continue even if it is not authenticated, and it won't install it.. -
"We don't sign our packages, so there is no gpg key. "
As a dedicated lover-of-the-Miro I've gotta ask: Why the decision to not sign your own packages? -
Just Curious ???
I have read the posts here, but have only seen one from an employee. That was back in '08. Is that because "MIRO" does not plan on implementing a gpg_key? If so thats too bad.
I even hesitated signing up to post because not sure I can trust your security. -
Inappropriate?me too , lame
I use miro on all my fedora installs,
+ plus I have to sign in to add another comment
I am out of here and deleting the Intrepid repo
Lame
I’m frustrated
-
Inappropriate?Please add a gpg key. It's a bit annoying to get those (unnecessary) warnings. And also, if you added all the commands to one code-line, people could simply copy/paste that line into their terminal and everything would be okay in a jippy.
I’m seeing things in need of improvement
-
Inappropriate?Yes, please add a GPG key as per Carl's request...
-
Inappropriate?I don't add third-party repositories that don't provide a GPG key. Why? Mostly because of apt's "WARNING: The following packages cannot be authenticated!" message. See, it conjures the bit of paranoia in me which I enjoy leaving dormant.
Do your part in helping to keep paranoia dormant.
It's on-par with feeding starving children.
I’m flatline-mouth :|
-
Inappropriate?From a modern security standpoint, it's almost negligent not to provide authentication for packages you intend for distribution, let alone mainstream adoption. The general philosophy of "openness" is incongruous with "insecurity." The Miro repository needs a secure key; otherwise, I cannot justify using the application, which is unfortunate considering its prime candidacy for deployment in our software image.
I’m unhappy
-
Inappropriate?Not to mention the pomposity oozing from the over-simplified "We don't sign our packages, so there is no gpg key." response.
It might as well read: "Meh."
With that said, I've been without Miro for a bit now and life seems to be rather okay. Although a nice alternative by creators that put effort into signing packages while refraining from sardonic answers on Get Satisfaction would be quite spiffy.
I’m whoa, donkey - slow down.
-
Inappropriate?Is there any help or support the community can provide to the Miro developers to facilitate this implementation?
I’m confident
-
Is there any reason why Miro doesn't use a launchpad ppa? Those use gpg keys automatically. -
This reply was removed on 06/28/09.
see the change log -
Inappropriate?WARNING: The following packages cannot be authenticated!
miro
Install these packages without verification [y/N]? N
E: Some packages could not be authenticated
I’m frustrated
-
We all know the error. Posting it isn't really helpful.
Feel free to click "I have this problem too" at the top of the thread though. :) -
Home systems are unlikely to have any security problems caused by saying "yes" -
Inappropriate?Ummm,
Unlikely?????
Home systems.... as opposed to Work systems????
There are good practices and there are bad practices.
I treat my "Home systems" just as I would an enterprise system,
you may not, and that is your prerogative, but to post a comment like that is
slightly absurd. Unlikely is not good enough for proper security - period.
That's like the Captain of the Titanic saying, Most ships are unlikely to sink if they hit a little ice. Come on.
I am not flaming you, nor the developers. I am standing by my assertion that signing keys are warranted here. They have been used in modern distributions easily since around 2000. It's 2009 let's get up to snuff.
An unsigned package = a not installed package. It's a non-starter. -
Inappropriate?I can not believe the attitude of developers on this! I used miro and I loved it! Then I reinstalled my distro, now im installing miro again and i noticed this warning about unsigned packages and so i googled here. I registered just to post this: I AM NOT going to install miro until there are signed packages. I will simply not use it at all. After all, life was as good before. We need free video. but we have to be sure it is free, not some trap. I cant believe its such a problem for the devs. or is there something more into it???
I’m dissapointed by whole project
-
Inappropriate?If you build your packages using the standard Debian process it even auto-signs your freshly created package set. You just have to enter the passphrase for the package signing key. It was designed specifically to be easy for the developers to sign their packages.
And, yes, package integrity is a big plus. You do not sign, so tampering on the distribution site will go unnoticed. Mass rollout of a modified program version willl go unnoticed. Miro is a software with full network access, so it would pose a strategic target if the installed base is big enough.
Please add package signing. It is worth the effort. Thank you.
I’m puzzled
Loading Profile...



EMPLOYEE



