Re: Your key B98321F9 is not on keyring.debian.org


On Mon, 04 Jul 2011 13:06:54 +0200, Martin Neitzel wrote:
our recent debmirror runs warned about failing gpg checks.  Turns out
that the squeeze pkg list is signed twice, based on both 473041FA and
B98321F9.  We still lacked the latter.  While I was able to retrieve
it from sks-keyservers.net, it is missing from keyring.debian.org.
You might want to add it there, too.

473041FA is the ftp-master archive key for Squeeze, whereas B98321F9 is the Squeeze stable release key. In fact, neither key is exported via keyring.debian.org, presumably because they are not part of the Debian keyring, as they don't belong to Debian Developers or Debian Maintainers.

Both keys are, however, part of the debian-archive-keyring package, together with the corresponding keys for lenny.

fwiw, the dual signing is not a recent change, so your debmirror setup should already have been failing to verify the signatures in that case.



