On Tue, 15 Jun 2010, Phil Schaffner wrote:
Just noticed that (at least some - e.g. CentOS-5 kernel-debuginfo, kernel-debuginfo-common, aspell-debuginfo) debuginfo packages are not signed. Started to file a bug entry, but don't know if it is merited. Is the intent to have these packages signed? The Debuginfo Wiki page shows "gpgcheck=1".
http://wiki.centos.org/AdditionalResources/Repositories/DebugInfo
It is intended, also see:
http://thomas.apestaart.org/log/?p=863
I answered Thomas after discussing with Karanbir and others. Obviously it's not a very good situation. I largely agree with Thomas' findings though, not with the tone of the message...