Wednesday January 17 2018

the official cd_dvd amd64 stable/stretch are not authentic/can't be
authentified : BAD


- LIVE DVD : idem

you published the keys/iso without have checked before their
validity/compatibility ?

gpg --verify sums512.sign sums512
gpg: Signature made Sun 10 Dec 2017 03:58:21 CET
gpg:                using RSA key DF9B9C49EAA9298432589D76DA87E80D6294BE9B
gpg: Can't check signature: No public key

gpg --keyserver keyring.debian.org --recv-key
gpg: key DA87E80D6294BE9B: public key "Debian CD signing key
<debian-cd@lists.debian.org>" imported
gpg: no ultimately trusted keys found
gpg: Total number processed: 1
gpg:               imported: 1

Signature made Sun 10 Dec 2017 03:58:21 CET
gpg:                using RSA key DF9B9C49EAA9298432589D76DA87E80D6294BE9B
gpg: BAD signature from "Debian CD signing key
<debian-cd@lists.debian.org>" [un

gpg --verify MD5SUMS.sign MD5SUMS
gpg: Signature made Sat 09 Dec 2017 09:58:24 PM EST
it sounds that these errors compromise apt-transport-https_sks ,
trusted.gpg.d (missing keys) _ sources.list.save & maybe gpg but i am not
certain of that.

*keys have changed new Sun 10 Dec 2017_old Sat 09 Dec 2017.

it is bizarre that before the linux security update the signature made Sat
09 Dec 2017 was good but today , it is bad.
does not an updated-key remember its revoked-key one (same cd-key) ?
should not it be written revoked instead of bad ?
is something wrong in the keyring ?
stolen-falsified keys/hacked site ?
a segment-fault on a server ?
fake debian.org site (i verified the cert(green) with the help of the
calomel-addon & i did not notice something wrong.)?

9.0. is not available (9.3 only ! ).
could you put on line asap the debian 9.0.0. stretch stable or update
9.3.0. with the right keys ?


*or my gtkhash/cli is broken and reporting this is a big error but in case
of doubt i do it , sorry.


