[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Package upload failed only due GPG expiration?



On Wed, Feb 02, 2022 at 11:50:47AM +0100, Filip Hroch wrote:
> I'm attempting to upload Fitspng into ftp-master, unfortunately, without any
> success. Moreover, I haven't received any message why the upload has been
> rejected, or anything else. 
When a valid signature is not found the uploader indeed doesn't get any
notifications.

From coccia.debian.org:/srv/ftp-master.debian.org/log/current:

20220202110344|process-upload|dak|fitspng_2.0-1_amd64.changes|Error while loading changes file fitspng_2.0-1_amd64.changes: No valid signature found. (GPG exited with status code 0)
gpg: Signature made Mon Jan 31 21:59:10 2022 UTC
gpg:                using RSA key 50329FD7732E2AB08161435F1E625DF64972FF9A
gpg:                issuer "hroch@physics.muni.cz"
gpg: Good signature from "Filip Hroch <hroch@physics.muni.cz>" [expired]
gpg: WARNING: Using untrusted key!

> By following of suggestions related on the post, and knowing that
> my GPG key has expired 2022-01-25, I uploaded renewed key
> on hkp://keyring.debian.org during Sunday. However, keycheck
> https://nm.debian.org/process/867/keycheck/ still indicates
> the expiration, and rsync confirms that the last keyring
> update was, accidentally, 25. January.
> 
> Now, I'm in doubts if the problem is related on the expiration,
> or if there is something different which should be investigated
> as well as.
Yes, it's because of key expiration.
Unfortunately I have no idea anymore which is the source of key data for
the upload processing as that's inconsitent and I don't know if it's
documented anywhere.

-- 
WBR, wRAR

Attachment: signature.asc
Description: PGP signature


Reply to: