Skip to content

[Docs] apt-key is deprecated #2893

Description

@dantman

The installation docs apt based systems includes an apt-key command: https://github.com/cli/cli/blob/trunk/docs/install_linux.md#debian-ubuntu-linux-apt

Running the recommended command results in the following warning:

Warning: apt-key is deprecated. Manage keyring files in trusted.gpg.d instead (see apt-key(8)).

The docs should probably be updated.

Activity

  1. mislav commented on Feb 2, 2021

    @mislav
    Contributor

    Thanks for letting us know! Weird that apt-key would get deprecated without a replacement.

    According to this, it seems that the solution is to do curl and write to files manually? docker/docs#11625 (comment)

  2. FranklinYu commented on Feb 3, 2021

    @FranklinYu

    According to this, it seems that the solution is to do curl and write to files manually?

    I think so. At a glance, this /usr/share/keyrings/ way (together with signed-by parameter) sounds more secure than apt-key or trusted.gpg.d, since it only allows this key to sign a single package source.

  3. mislav commented on Feb 3, 2021

    @mislav
    Contributor

    We welcome PRs that change our installation docs to replace the apt-key step with a more suitable alternative. Ideally, the new instructions would also work on all systems where apt-key used to work. Thank you!

  4. redfire75369 commented on Apr 4, 2021

    @redfire75369

    My initial testing with this has not worked well so far

    $ curl -fsS -o - "http://keyserver.ubuntu.com/pks/lookup?op=get&search=0xC99B11DEB97541F0" | gpg --dearmor | sudo tee /usr/share/keyrings/gh-archive-keyring.gpg
    $ echo "deb [arch=amd64 signed-by=/usr/share/keyrings/gh-archive-keyring.gpg] https://cli.github.com/packages bullseye main" | sudo tee /etc/apt/sources.list.d/gh.list

    sudo apt update outputs

    Err:2 https://cli.github.com/packages bullseye InRelease
      The following signatures couldn't be verified because the public key is not available: NO_PUBKEY C99B11DEB97541F0
    
  5. lxvm commented on Apr 5, 2021

    @lxvm

    This worked for me:

    If you've been trying this some time, first delete the key from the root user's keyring in the two places you might find it:

    # if
    $ sudo gpg -k
    /root/.gnupg/pubring.kbx
    ------------------------
    pub   rsa3072 2020-09-02 [SC] [expires: 2022-09-02]
          2CA32056ED206CB81F44A8CAC99B11DEB97541F0
    uid           [ unknown] Nate Smith <[email protected]>
    sub   rsa3072 2020-09-02 [E] [expires: 2022-09-02]
    
    # then
    $ sudo gpg --delete-keys 2CA32056ED206CB81F44A8CAC99B11DEB97541F0
    gpg (GnuPG) 2.2.27; Copyright (C) 2021 Free Software Foundation, Inc.
    This is free software: you are free to change and redistribute it.
    There is NO WARRANTY, to the extent permitted by law.
    
    
    pub  rsa3072/C99B11DEB97541F0 2020-09-02 Nate Smith <[email protected]>
    
    Delete this key from the keyring? (y/N) y
    
    # and
    $ keyfile=/usr/share/keyrings/gh-archive-keyring.gpg; if [ -f $keyfile ]; then sudo rm $keyfile; fi
    

    Then download the key to the keyring

    $  sudo gpg --no-default-keyring --keyring /usr/share/keyrings/gh-archive-keyring.gpg --keyserver keyserver.ubuntu.com --search-keys C99B11DEB97541F0
    gpg: keybox '/usr/share/keyrings/gh-archive-keyring.gpg' created
    gpg: data source: http://162.213.33.9:11371
    (1)	Nate Smith <[email protected]>
    	  3072 bit RSA key C99B11DEB97541F0, created: 2020-09-02
    Keys 1-1 of 1 for "C99B11DEB97541F0".  Enter number(s), N)ext, or Q)uit > 1
    gpg: key C99B11DEB97541F0: public key "Nate Smith <[email protected]>" imported
    gpg: Total number processed: 1
    gpg:               imported: 1
    

    Note: I learned this command from this online tutorial.

    Add the signed entry to apt's sources

    $ echo "deb [arch=amd64 signed-by=/usr/share/keyrings/gh-archive-keyring.gpg] https://cli.github.com/packages bullseye main" | sudo tee /etc/apt/sources.list.d/gh.list
    

    Note: I think you can replace bullseye with the distro installed on your machine

    Update the apt configuration

    $ sudo apt update
    Hit:1 https://apt.repos.intel.com/oneapi all InRelease
    Get:2 https://cli.github.com/packages bullseye InRelease [3,747 B]             
    Hit:3 http://security.debian.org/debian-security bullseye-security InRelease   
    Hit:4 http://deb.debian.org/debian bullseye InRelease                   
    Get:5 https://cli.github.com/packages bullseye/main amd64 Packages [338 B]
    Fetched 338 B in 1s (411 B/s)                     
    Reading package lists... Done
    Building dependency tree... Done
    Reading state information... Done
    All packages are up to date.
    

    I'm using Debian testing and would hope this also works for other apt-based distros with the appropriate modifications to the apt sources

  6. redfire75369 commented on Apr 6, 2021

    @redfire75369

    I am aware this method works on most distributions. However, the issue is that this method isn't universal as it does not work on WSL.
    You get an error along the lines of

    gpg: failed to create temporary file '/root/.gnupg/.#lk0x000055999c2c7bd0.Lenovo-G480.546': No such file or directory
    gpg: connecting dirmngr at '/root/.gnupg/S.dirmngr' failed: No such file or directory
    gpg: error searching keyserver: No dirmngr
    gpg: keyserver search failed: No dirmngr

    See: microsoft/WSL#3286

  7. lxvm commented on Apr 6, 2021

    @lxvm

    I also had the dirmngr problem on Debian and think it was because /root/.gnupg didn't exist.
    I reproduced the problem on WSL2 Debian Bullseye (which might be new enough to not have the bug found in the issue you linked) by doing $ sudo mv /root/.gnupg /root/something and then trying to download the key.

    To fix the problem, I ran $ sudo dirmngr, which sets up /root/.gnupg, and then I downloaded the key without any problem.
    I think you can also run $ sudo gpg to do the same.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingdocshelp wantedContributions welcome

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions