[Top][All Lists]

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

bug#17625: 24.4.50; All installed packages marked "unsigned", no archive

From: Glenn Morris
Subject: bug#17625: 24.4.50; All installed packages marked "unsigned", no archive listed
Date: Sat, 21 Jun 2014 19:50:57 -0400
User-agent: Gnus (www.gnus.org), GNU Emacs (www.gnu.org/software/emacs/)

Glenn Morris wrote:

> I suggest creating a test package on elpa.gnu.org that is signed to see
> how it works.

Is anyone interested in doing this?
This feature seems like it might be almost there, so IMO it would seem
like a shame to release 24.4 without ever testing this in the wild.

> If package-check-signature has its default value, `allow-unsigned', you
> can happily install a package with no signature, but trying to install
> one that _is_ signed, but for which you don't have the public key, fails
> with "Failed to verify signature".

I think that is a potential show-stopper. 
Perhaps archives could also provide keys for download in a standard location.
The first time you connect to a given archive, Emacs could offer to
download and import the key (with a suitable warning). Or is this crazy?

reply via email to

[Prev in Thread] Current Thread [Next in Thread]