[Pkg-mono-devel] no private key (was Re: E: installing Assembly /usr/lib/cli/Kitware.mummy.Runtime-1.0/Kitware.mummy.Runtime.dll failed)
Jo Shields
directhex at apebox.org
Tue Mar 8 10:47:39 UTC 2011
On Tue, 2011-03-08 at 11:40 +0100, Mathieu Malaterre wrote:
> just FYI. I finally found what was the issue. Upstream is only
> shipping the public portion of key (as far as I understand):
>
> ./Runtime/Kitware.mummy.Runtime.pub.snk
>
> This is not sufficient apparently. As recommended on :
>
> http://pkg-mono.alioth.debian.org/cli-policy/ch-packaging.html#s-signing
>
> I must use the private+public key from the cli-common-dev package.
>
> Any reason why upstream would only be shipping the public portion of the key ?
I guess to stop evil hackers from building modified versions. Which
sorta defeats the purpose of being open-source, somewhat.
It wouldn't be the first time we ship something with our own key, but it
sadly means we lose compatibility with binaries built against the "real"
thing.
More information about the Pkg-mono-devel
mailing list