debmirror, GPG, Stretch

After downloading Release and Release.gpg, debmirror hangs (uses
100% CPU until killed).

My guess is that there's a bug in the signature verification
code that is triggered by the absence of the key in
/usr/share/keyrings/debian-archive-keyring.gpg and friends (this
being a Debian 8 system).

Unfortunately, since debmirror never gets to where it tells me
what signature it couldn't verify, I don't know what key to gpg
--recv-key; gpg --export | apt-key add.

This is where a list of key IDs used for ftp.debian.org would
come in handy. But if it exists, it's not easy to find.

No doubt keys can be found by looking into the latest release of
debian-archive-keyring or poking strings into a search engine
until you get lucky. What I'd like to know is where are we
*supposed* to look for them ?

Thanks in advance.

André Majorel <http://www.teaser.fr/~amajorel/>
The Debian project must be praised for their efforts in figthing
spam by never exposing the email addresses of their users.

