[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#345823: apt: Key error at year turnover resembles security problem, and may represent one



I came across the same error this morning. The part that was rather
frustrating is that I had no idea where to find the new key.  Only by
returning to the bug report (where Joey H provided a link) was I able to
find it.

http://ftp-master.debian.org/ziyi_key_2006.asc

Most users do not think to check ftp-master.

It would be nice to update the following places (where I looked for the
new key and found none):

* http://www.debian.org/security/faq

There's a link to the old key under Q: How can I check the integrity of
packages?

* keyring.debian.org

I tried to download the new key from the above key server using the key
id and found none.

Also, 'apt-key update' gives one the impression that the problem is
easily fixable but it leads to disappointment.

# apt-key update
ERROR: Can't find the archive-keyring
Is the debian-keyring package installed?

After installing debian-keyring, the same error occurs (presumably
because of changed filenames?).  I suspect the new public key is not in
the debian-keyring package anyway.

Regards,
Ed



Reply to: