[Pkg-gnupg-maint] Bug#592902: Bug#387688: Add gnupg as apt dependency in Squeeze to be able to solve #387688 in Squeeze+1?

Philipp Kern pkern at debian.org
Sun Aug 22 09:24:14 UTC 2010


On 08/22/2010 12:46 AM, Carsten Hey wrote:
> By removing the (currently indirect) apt dependencies on gnupg and
> libusb-0.1-4 and making apt depend on gpgv (or gpgv | gpgv-tiny)
> instead, 5272 kB could be saved.  There are ways to accomplish this for
> Squeeze+1, how it could be done seems to be nothing that needs to be
> discussed before Squeeze is released.
>    

Please note that, due to how apt currently handles keyrings, you do need 
a full gnupg available to run apt-key.  The use of gpgv is only 
implemented in the installer, as it uses only one keyring file.  An 
alternative might be looping over several keyrings using gpgv, to verify 
the signature, instead of using a large one.  But this wasn't 
implemented yet, of course.

Kind regards,
Philipp Kern





More information about the Pkg-gnupg-maint mailing list