Devuan bug report logs - #705
Update failed due to an invalide signature

Package: amprolla; Maintainer for amprolla is Devuan Developers <devuan-dev@lists.dyne.org>;

Reported by: Klaus Ethgen <Klaus@ethgen.de>

Date: Mon, 5 Sep 2022 07:20:01 UTC

Severity: critical

Merged with 704

Done: Mark Hindley <mark@hindley.org.uk>

Full log


🔗 View this message in rfc822 format

X-Loop: owner@bugs.devuan.org
Subject: bug#705: [devuan-dev] bug#705: Acknowledgement (Update failed due to an invalide signature)
Reply-To: Daniel Reurich <daniel@centurion.net.nz>, 705@bugs.devuan.org
Resent-From: Daniel Reurich <daniel@centurion.net.nz>
Resent-To: devuan-bugs@lists.dyne.org
Resent-CC: devuan-dev@lists.dyne.org
X-Loop: owner@bugs.devuan.org
Resent-Date: Mon, 05 Sep 2022 21:32:09 +0000
Resent-Message-ID: <handler.705.B705.16624134128667@bugs.devuan.org>
Resent-Sender: owner@bugs.devuan.org
X-Devuan-PR-Message: followup 705
X-Devuan-PR-Package: devuan
X-Devuan-PR-Keywords: 
References: <YxWi7GN6UjFhvWaG@ikki.ethgen.ch> <handler.705.B.166236237917527.ack@bugs.devuan.org> <YxWi7GN6UjFhvWaG@ikki.ethgen.ch> <YxWrAZF+oHdmvQHa@ikki.ethgen.ch> <YxWi7GN6UjFhvWaG@ikki.ethgen.ch>
Received: via spool by 705-submit@bugs.devuan.org id=B705.16624134128667
          (code B ref 705); Mon, 05 Sep 2022 21:32:09 +0000
Received: (at 705) by bugs.devuan.org; 5 Sep 2022 21:30:12 +0000
Delivered-To: devuanbugs@dyne.org
Received: from mail.dyne.org [141.95.83.167]
	by doc.devuan.org with IMAP (fetchmail-6.4.16)
	for <debbugs@localhost> (single-drop); Mon, 05 Sep 2022 21:30:12 +0000 (UTC)
Received: from mbx.knossos.net.nz (mbx.knossos.net.nz [202.160.48.10])
	by mail.dyne.org (Postfix) with ESMTP id CF4FF66189E
	for <705@bugs.devuan.org>; Mon,  5 Sep 2022 23:29:38 +0200 (CEST)
Received: from [192.168.2.146] (crm.2serve.nz [202.160.51.126])
	(authenticated bits=0)
	by mbx.knossos.net.nz (8.14.4/8.14.4) with ESMTP id 285LTRj6029514
	(version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=NOT);
	Tue, 6 Sep 2022 09:29:32 +1200
Message-ID: <4aa6136d-7b31-7e05-ea2a-8e4c9b24ed37@centurion.net.nz>
Date: Tue, 6 Sep 2022 09:29:26 +1200
MIME-Version: 1.0
Content-Language: en-US
To: Klaus Ethgen <Klaus@ethgen.de>, 705@bugs.devuan.org,
        devuan developers internal list <devuan-dev@lists.dyne.org>
From: Daniel Reurich <daniel@centurion.net.nz>
In-Reply-To: <YxWrAZF+oHdmvQHa@ikki.ethgen.ch>
Content-Type: multipart/signed; micalg=pgp-sha256;
 protocol="application/pgp-signature";
 boundary="------------uRLBj54cC1Db9rJyMrengy04"
X-Spam-Status: No, score=0.0 required=5.0 tests=URIBL_BLOCKED
	autolearn=disabled version=3.4.2
X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on mail.dyne.org
[Message part 1 (text/plain, inline)]
Yes the key expired, and I probably noticed first by virtue of living in 
the future compared to everyone else.

We should be adding a new signing key each release for the next future 
release, and ensuring it will endure for at least 2 future release. 
This should be done immediately following a release.

This should be part of our "New Release - Devuan Devs guide to managing 
the new release process." - if such a document should exist.  (If it 
doesn't maybe we should create it.)

Regards,
	Daniel

On 5/09/22 19:53, Klaus Ethgen wrote:
> Hi,
> 
> The reason seems to be that the key is expired.
> 
> The mitigation might be difficult. But you might have the way to do so.
> Just sign the repository with the key
> 72E3CB773315DFA2E464743D94532124541922FB instead of
> E032601B7CA10BC3EA53FA81BB23C00C61FC752C.
> 
> 72E3CB773315DFA2E464743D94532124541922FB is in
> /etc/apt/trusted.gpg.d/devuan-keyring-2016-archive.gpg and never expire.
> 
> After some months, just create a new key which never expire or expire
> far in the future and use that for the repository.
> 
> Regards
>     Klaus
> 
> 
> _______________________________________________
> devuan-dev internal mailing list
> devuan-dev@lists.dyne.org
> https://mailinglists.dyne.org/cgi-bin/mailman/listinfo/devuan-dev


-- 
Daniel Reurich
Centurion Computer Technology (2005) Ltd.
021 797 722
[OpenPGP_signature (application/pgp-signature, attachment)]

Send a report that this bug log contains spam.


Devuan BTS -- Powered by Debian bug tracking system
Copyright (C) 1999 Darren O. Benham,
1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson,
2005-2017 Don Armstrong, and many other contributors.

Devuan Bugs Owner <owner@bugs.devuan.org>.
Last modified: Sun Apr 28 19:55:34 2024;