Ben Hutchings <b...@decadent.org.uk> writes:

> It is true that this package cannot be auto-built, but it does not
> need to be.  This is explained in debian/README.source.

That explains *how* to build it by hand, certainly.

But of what use is the signature if the package can just install
whatever public key anyway?  Would there be any nasty consequences if
the package sources included a "private" key that was used to sign
the database?

(Also, the crda(8) manpage on wheezy claims that it will only use
databases signed by John Linville.  If that's not so, shouldn't the
manpage be fixed?)

--
Sam Bronson


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Reply via email to