Skip Menu |

This queue is for tickets about the Travel-UK-London-Tube CPAN distribution.

Report information
The Basics
Id: 70093
Status: resolved
Priority: 0/
Queue: Travel-UK-London-Tube

People
Owner: MANWAR [...] cpan.org
Requestors: ANDK [...] cpan.org
Cc:
AdminCc:

Bug Information
Severity: Normal
Broken in: 0.02
Fixed in: 0.03



Subject: Signed with an unknown key
Trying to verify your signature: cpansign -v Executing gpg --verify --batch --no-tty --keyserver=hkp://pool.sks-keyservers.net:11371 --keyserver-options=auto-key-retrieve SIGNATURE gpg: Signature made Sat 30 Apr 2011 10:51:20 AM CEST using RSA key ID A8EC2FE9 gpg: requesting key A8EC2FE9 from hkp server pool.sks-keyservers.net gpgkeys: key DA172575A8EC2FE9 not found on keyserver gpg: no valid OpenPGP data found. gpg: Total number processed: 0 gpg: Can't check signature: public key not found Maybe you never uploaded the key A8EC2FE9 to a public key server? BTW, I found the same problem on TV-ProgrammesSchedules-STAR-0.04.tar.gz Thanks && Regards,
Hi Andreas, Thanks for the bringing this to my notice. I have now uploaded A8EC2FE9 to public server. Could you please confirm if this is OK at your end? Best Regards, Mohammad S Anwar
Thank you for the fast response. Yes, cpansign can now use your public key. But now there is a different problem that affects many of your uploads. In all those cases I see a MANIFEST file with mixed line endings, both LF and CRLF. The fault is not yours, I've just submitted a patch to ExtUtils::Manifest which explains and should fix the root cause: https://rt.perl.org:443/rt3/Ticket/Display.html?id=96408 Since there was another EOL related bug in Module::Signature that has been fixed in version 0.68, I cannot verify your signatures with 0.68 anymore. Module::Signature is tolerant when line endings on text files have been modified but it is not tolerant when text files have mixed EOLs. This means you would either have to fix your MANIFEST files to have only one type of line ending or you would have to use Module::Signature 0.68 for signing. The distros I found affected besides Travel::UK::London::Tube so far are: TV-ProgrammesSchedules-BBC-0.08.tar.gz TV-ProgrammesSchedules-STAR-0.04.tar.gz TV-ProgrammesSchedules-Sony-0.04.tar.gz Test-Excel-1.23.tar.gz WWW-Google-Diacritize-0.05.tar.gz WWW-Oyster-0.04.tar.gz I have not tried all your uploads. Sorry for the bad news and thanks again for the quick fix!
Hi Andreas, I would fix all the affected modules you mentioned by signing using Module::Signature 0.68. Unfortunately this can only be done on monday 8th Aug'2011 at the earliest. Thanks for the suggestion. Best Regards, Mohammad S Anwar
Hi Andreas, As promised I have uploaded the following modules that you pointed out in your earlier email after building it with Module::Signature v0.68. TV-ProgrammesSchedules-Sony-0.05 TV-ProgrammesSchedules-STAR-0.05 TV-ProgrammesSchedules-BBC-0.09 Travel-UK-London-Tube-0.03 Test-Excel-1.24 WWW-Google-Diacritize-0.06 WWW-Oyster-0.05 Also I would be doing the same with the remaining 41 modules of mine in the next hour or so. Many Thanks for your time and suggestion. Best Regards, Mohammad S Anwar
CC: ANDK [...] cpan.org
Subject: Re: [rt.cpan.org #70093] Signed with an unknown key
Date: Mon, 08 Aug 2011 21:49:23 +0200
To: bug-Travel-UK-London-Tube [...] rt.cpan.org
From: andreas.koenig.7os6VVqR [...] franz.ak.mind.de (Andreas J. Koenig)
Show quoted text
> Many Thanks for your time and suggestion.
I'm very, very impressed by your fast reaction. Thank you very, very much:)
Closing the ticket as it has been confirmed fixed.