-
-
Notifications
You must be signed in to change notification settings - Fork 403
Description
https://wiki.debian.org/DebianRepository/Format#Signed-By says:
Signed-By
An optional field containing a comma separated list of OpenPGP key fingerprints to be used for validating the next Release file. The fingerprints must consist only of hex digits and may not contain spaces. The fingerprint specifies either the key the Release file must be signed with or the key the signature key must be a subkey of. The later match can be disabled by appending an exclamation mark to the fingerprint.If the field is present, a client should only accept future updates to the repository that are signed with keys listed in the field. The field should be ignored if the Valid-Until field is not present or if it is expired.
Unless i'm really missing it, aptly does not produce this field,
and can not be configured to produce this field. Is that correct?
It would be nice if the value for that field could be configured,
with MVP being treating it as a opaque textual field without actual validation,
that can be configured during aptly publish (snapshot|repo).
Thank you!