Bug#775454: Allow user blocking of https fallback

2015-05-15 Thread jnqnfe
On Fri, 2015-05-15 at 04:58 +0200, Cyril Brulebois wrote: > Control: tag -1 pending > > jnqnfe (2015-01-15): > > Package: debootstrap > > Severity: important > > Tags: security patch > > > > In the event of a GPG keyring not being found, debootstrap may fallback > > to the alternative security o

Bug#775454: Allow user blocking of https fallback

2015-05-14 Thread Cyril Brulebois
Control: tag -1 pending jnqnfe (2015-01-15): > Package: debootstrap > Severity: important > Tags: security patch > > In the event of a GPG keyring not being found, debootstrap may fallback > to the alternative security of an https mirror. > > Users lacking the requisite GPG keyring file (or per

Bug#775454: Allow user blocking of https fallback

2015-01-15 Thread jnqnfe
Additional patch attached to update the manpages with regard to the new param introduced in the previously supplied patch. I believe I may have misread the code slightly when composing the initial bug report. I believe now that the matter only arises when the dist script tries to set the keyring f

Bug#775454: Allow user blocking of https fallback

2015-01-15 Thread jnqnfe
Package: debootstrap Severity: important Tags: security patch In the event of a GPG keyring not being found, debootstrap may fallback to the alternative security of an https mirror. Users lacking the requisite GPG keyring file (or perhaps just making a typo in their parameters) may not necessaril