Comment 18 for bug 413657

Revision history for this message
Scott Kitterman (kitterman) wrote : Re: Please sync tor 0.2.1.19-1 (universe) from Debian testing (main)

If I'm reading comment #4 correctly, we could only ever sync from Debian and not make our own changes to have a trusted signature. I don't think that would work out. At the version least we need to be able to have different package revision numbers for different releases when we do updates.

It seems to me like if we are going to do this, we would need some kind of plan like we use for clamav:

https://wiki.ubuntu.com/ClamavUpdates

If the signing key issue is important, we'll also need a MOTU who's key is trusted by TOR.