> So, having installed the key, should I still be getting messages from aptitude that firefox is untrusted? Or have I missed a step somewhere?
depends on your repo setup, which is noch completely clear. You could post the output of:
apt-cache policy firefox{,-esr}
which shows all candidates for the firefox and -esr name and which packages are candidates for that. Also
apt-key finger
shows which keys your apt installation trusts
regards, arian
Attachment:
signature.asc
Description: OpenPGP digital signature