12 Feb 2019 |
Maximus | I speak bad english | 02:03:44 |
Maximus | :] | 02:03:56 |
Maximus | On this humourous (sic) note, bed time. Thank you again Linda for the detailed explaination and talk to you tomorrow for a follow-up | 02:05:38 |
Linda | same, bed-time after I finish my meal | 02:05:51 |
Maximus | nn | 02:06:01 |
| anoa joined the room. | 13:08:40 |
Linda | I have a working package matrix-archive-keyring-2015.12.09+debian1 , which installs the keys to /usr/share/keyrings and removes known untrusted keys from /etc/apt/trusted.gpg{,d} . It doesn't do anything with sources.list.d , yet. | 17:00:10 |
andrewsh | I’m not certain how much such a package is necessary though… | 17:52:57 |
andrewsh | ideally, Debian users wouldn’t need to install anything at all from matrix.org | 17:53:50 |
andrewsh | by the way, this package is in any case too late for Buster | 17:54:06 |
andrewsh | since the soft freeze starts tonight | 17:54:14 |
andrewsh | speaking of which, bad news: the new ACME thing won’t be in Buster 😕 | 17:55:10 |
andrewsh | unless we convince the release managers to make an exception and let txacme and related things into testing during the soft freeze | 17:55:36 |
andrewsh | richvdh: ^ | 17:55:46 |
andrewsh | another option would be to bundle a vendored copy of it but I would prefer to avoid that | 17:56:34 |
andrewsh | richvdh: is there a way to hack something without txacme but just using the Python acme package we already have in Debian | 17:57:09 |
Linda | I know about the freeze, yeah | 17:58:23 |
Linda | That is the ideal, but I just sent a WNPP ITP | 17:58:37 |
Linda | https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=922155 | 17:59:23 |
andrewsh | thanks | 18:00:50 |
andrewsh | (just to clarify: I don’t oppose this package at all, I’m just not certain about the usefulness of it) | 18:01:22 |
Linda | Would you be willing to sponsor it, please? | 18:02:03 |
andrewsh | sure | 18:02:17 |
andrewsh | richvdh: what’s the internal policy regarding that key? | 18:02:27 |
andrewsh | richvdh: what else do you sign using it? how do you manage who has access to it? are there any other keys in use? | 18:03:02 |
Linda | I don't have an account on Salsa, but I can send you the tarball and related build files if you'd like to sponsor it | 18:05:13 |
andrewsh | you can create an account yourself if you like | 18:11:48 |
andrewsh | or you can publish a Git tree wherever you like | 18:12:00 |
andrewsh | but I’m fine with a tarball | 18:12:15 |
Linda | Well, here's a preview | 18:14:17 |