Re: Checking GPG Signatures - Debian Keyring is Huge !

2007-03-15 Thread Joey Hess
Nick Boyce wrote: > It certainly is dated 2005 - perhaps it's ancient history, but it's the > only key-related file at http://ftp.debian.org/debian/doc/ ... looks > like maybe we need a tidy-up of that part of the website. Well, 2005 is when the debian-keyring package was last updated, although of

Re: Checking GPG Signatures - Debian Keyring is Huge !

2007-03-14 Thread Nick Boyce
Sven Arvidsson wrote: > I think you're looking at a keyring of all the debian developers (an > outdated copy from 2005 it seems) that's not necessary to download. It certainly is dated 2005 - perhaps it's ancient history, but it's the only key-related file at http://ftp.debian.org/debian/doc/ ..

Re: Checking GPG Signatures - Debian Keyring is Huge !

2007-03-14 Thread Sven Arvidsson
On Wed, 2007-03-14 at 23:08 +, Nick Boyce wrote: > [Just for completeness, and more to the point, but not wanting to flog a > dead horse]: I should have added, when you're on dial-up (yes .. some of > us still are) every 13Mb download is painful ... compared with the 2K > (say) that a separate

Re: Checking GPG Signatures - Debian Keyring is Huge !

2007-03-14 Thread Nick Boyce
I wrote: > Stephen Cormier wrote: > >> Have you tried/heard of the --keyring option when using gpg? That way you >> only >> need to specify the file containing the key not add it to your own keyring. > > I guess I could do that - I suppose I could also extract the relevant > key from the Debian

Re: Checking GPG Signatures - Debian Keyring is Huge !

2007-03-13 Thread Nick Boyce
Stephen Cormier wrote: > On March 13, 2007 11:04:44 pm Nick Boyce wrote: >> Do I *really* need to add such a large keyring to my own keyring, just >> to verify the dang GPG signature on a CD image ? > > Have you tried/heard of the --keyring option when using gpg? That way you > only > need to sp

Re: Checking GPG Signatures - Debian Keyring is Huge !

2007-03-13 Thread Stephen Cormier
On March 13, 2007 11:04:44 pm Nick Boyce wrote: > Do I *really* need to add such a large keyring to my own keyring, just > to verify the dang GPG signature on a CD image ? Have you tried/heard of the --keyring option when using gpg? That way you only need to specify the file containing the key no

Checking GPG Signatures - Debian Keyring is Huge !

2007-03-13 Thread Nick Boyce
So ... I just downloaded a Debian Sarge CD image, checked the MD5 sum was okay, and then just for completeness figured I'd check the GPG signature on the MD5 sums file ... GPG told me I needed DSA key id 88C7C1F7 to verify the signature ... http://www.debian.org/CD/faq/#verify tells me I can get