Comment 6 for bug 125103

Revision history for this message
Dave Walker (davewalker) wrote :

I don't think there should be a general key for all PPA's. I think it is quite important for separate users/projects to have their own keys, as mentioned above - to trust one user/projects archive is different to a blanket approval.

I also think that LP could make adding of public key's easier, maybe building them into packages with a clicky "APT:" link that prior to allowing download, warns the user that they must use their judgement in adding the key, whether or not they trust the owner.

Mass roll out of PPA approval could be potentially dangerous, I have an underlying security concern that I'd rather not publish here - but could be disastrous for *many* users. Prior to implementation of this feature I would like to discus this further with the PPA dev' team