Package: ubuntu-dbgsym-keyring
Version: 2018.09.18.1-4
Severity: normal

Dear Maintainer,

the following files are in a GPG keybox database version 1 format.

- keyrings/ubuntu-dbgsym-keyring.gpg
- keyrings/ubuntu-dbgsym-removed-keys.gpg

As said in the apt-key(8) man page:

> apt-key supports only the binary OpenPGP format (also known as "GPG
> key public ring") in files with the "gpg" extension, not the keybox
> database format introduced in newer gpg(1) versions as default for
> keyring files.

$ file keyrings/ubuntu-dbgsym-keyring.gpg 
keyrings/ubuntu-dbgsym-removed-keys.gpg
keyrings/ubuntu-dbgsym-keyring.gpg:      GPG keybox database version 1, 
created-at Thu Feb  1 12:47:14 2018, last-maintained Thu Feb  1 12:47:14 2018
keyrings/ubuntu-dbgsym-removed-keys.gpg: GPG keybox database version 1, 
created-at Thu Feb  1 12:47:35 2018, last-maintained Thu Feb  1 12:47:35 2018

The latter of these keyringss can be configured with debconf(1) to be
installed as an APT trust anchor. This won't work.
(ubuntu-dbgsym-keyring.gpg does not seem to be offered?)

The issue is not as severe, because this is not the default behavior for
the package. It may also be rather unlikely anyone would install the
removed keys.


-- System Information:
Debian Release: buster/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: amd64 (x86_64)

Kernel: Linux 4.19.0-2-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), 
LANGUAGE=en_US:en (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages ubuntu-dbgsym-keyring depends on:
ii  debconf [debconf-2.0]  1.5.70

Versions of packages ubuntu-dbgsym-keyring recommends:
ii  gpgv  2.2.12-1

ubuntu-dbgsym-keyring suggests no packages.

apt 1.8.0~rc3.

Reply via email to