OpenARC icon indicating copy to clipboard operation
OpenARC copied to clipboard

Release Key for OpenARC Builds has expired

Open MrPeteH opened this issue 4 years ago • 5 comments

It's a bit tough to install without a current key ;) https://download.opensuse.org/repositories/home:/andreasschulze/Debian_10/Release.key

Workaround: deb [allow-insecure=yes] https://download.opensuse.org/repositories/home%3A/andreasschulze/Debian_10 ./

MrPeteH avatar Dec 15 '21 16:12 MrPeteH

OpenARC releases in this repository are not signed.

Better report this wherever you found the signed artefact. There is nothing that can be done here.

glts avatar Dec 15 '21 17:12 glts

I will try to find him... unfortunately, the openarc email listserver also appears busted: it doesn't confirm a subscribe...

MrPeteH avatar Dec 15 '21 17:12 MrPeteH

the key was automatically updated today. Could you contact me directly with information about your your issues with the listserver?

andreasschulze avatar Dec 21 '21 20:12 andreasschulze

On 2021-12-21 21:58, A. Schulze wrote:

the key was automatically updated today. Could you contact me directly with information about your your issues with the listserver?

plase turn off html, sorry github is a mua client aswell imho

xpunkt avatar Dec 21 '21 21:12 xpunkt

Ugh. @andreasschulze infrastructure changes in the Debian/Ubuntu apt-* world have obsoleted quite a few signing methodologies. I've gotten as far as finding a set of commands that can convert an auto-created Release.key file into a valid signature in a "modern" no-more apt-key context. This can probably be simplified... and I suspect there's an appropriate new keyring file that opensuse (??) ought to be providing (see https://wiki.debian.org/DebianRepository/UseThirdParty#OpenPGP_certificate_distribution)

(My source of insight for the following is the top answer in https://askubuntu.com/questions/1286545/what-commands-exactly-should-replace-the-deprecated-apt-key )

#all under sudo
wget https://download.opensuse.org/repositories/home:/andreasschulze/Debian_11/Release.key
gpg --no-default-keyring --keyring ./temp-keyring.gpg --import Release.key
gpg --no-default-keyring --keyring ./temp-keyring.gpg --export --output home_andreasschulze.gpg
rm temp-keyring.gpg*
mkdir /etc/apt/keyrings
chmod 755 /etc/apt/keyrings
mv home_andreasschulze.gpg /etc/apt/keyrings/

Now insert the following or equivalent into sources.list.d/openarc.list deb [signed-by=/etc/apt/keyrings/home_andreasschulze.gpg] http://download.opensuse.org/repositories/home:/andreasschulze/Debian_11/ / Voila, updates are again working.

MrPeteH avatar Mar 16 '24 14:03 MrPeteH