Re: [pgsql-pkg-debian] Re: We should not transition to apt.postgresql.org until we have a PPA

From: Martin Pitt <mpitt(at)debian(dot)org>
To: Magnus Hagander <magnus(at)hagander(dot)net>
Cc: Martin Pitt <mpitt(at)debian(dot)org>, Greg Smith <greg(at)2ndquadrant(dot)com>, Bruce Momjian <bruce(at)momjian(dot)us>, Alvaro Herrera <alvherre(at)2ndquadrant(dot)com>, Christoph Berg <myon(at)debian(dot)org>, Stefan Kaltenbrunner <stefan(at)kaltenbrunner(dot)cc>, Josh Berkus <josh(at)agliodbs(dot)com>, PostgreSQL WWW <pgsql-www(at)postgresql(dot)org>, PostgreSQL in Debian <pgsql-pkg-debian(at)postgresql(dot)org>, Tom Lane <tgl(at)sss(dot)pgh(dot)pa(dot)us>
Subject: Re: [pgsql-pkg-debian] Re: We should not transition to apt.postgresql.org until we have a PPA
Date: 2013-02-19 16:01:56
Message-ID: 20130219160156.GJ3033@piware.de
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-pkg-debian pgsql-www

Magnus Hagander [2013-02-19 16:40 +0100]:
> Unfortunately, it will take quite a while to propagate, no?

Yes, but it took a long time to set up apt.p.o, and the PPA won't
disappear anytime soon anyway. This is also something which we can
backport to 12.04 LTS, and 10.04 LTS' lifetime isn't that long any
more anyway. For Debian, there's a good chance we can get it into the
next release (wheezy); it's in deep freeze, but that's a low-risk
change.

> What we were considering was using a curl | sudo bash basically. It
> will then be signed by our main SSL certificate, so that should be
> almost as trustworthy as a package signature (ours would be
> exploitable by somebody tricking a public CA into giving them a cert
> for www.postgresql.org)

That seems fine indeed. There's nothing wrong with having more than
one way -- if you have the local script, use that, otherwise use above
approach?

Thanks,

Martin
--
Martin Pitt | http://www.piware.de
Ubuntu Developer (www.ubuntu.com) | Debian Developer (www.debian.org)

In response to

Responses

Browse pgsql-pkg-debian by date

  From Date Subject
Next Message Greg Smith 2013-02-19 18:52:09 Re: [pgsql-pkg-debian] Re: We should not transition to apt.postgresql.org until we have a PPA
Previous Message Andres Freund 2013-02-19 16:01:41 Re: [pgsql-pkg-debian] Re: We should not transition to apt.postgresql.org until we have a PPA

Browse pgsql-www by date

  From Date Subject
Next Message Greg Smith 2013-02-19 18:52:09 Re: [pgsql-pkg-debian] Re: We should not transition to apt.postgresql.org until we have a PPA
Previous Message Andres Freund 2013-02-19 16:01:41 Re: [pgsql-pkg-debian] Re: We should not transition to apt.postgresql.org until we have a PPA