Repository navigation
[Docs] apt-key is deprecated #2893
Description
Activity
Thanks for letting us know! Weird that
apt-keywould get deprecated without a replacement.According to this, it seems that the solution is to do curl and write to files manually? docker/docs#11625 (comment)
According to this, it seems that the solution is to do curl and write to files manually?
I think so. At a glance, this
/usr/share/keyrings/way (together withsigned-byparameter) sounds more secure thanapt-keyortrusted.gpg.d, since it only allows this key to sign a single package source.Reacted by Daniel FriesenWe welcome PRs that change our installation docs to replace the
apt-keystep with a more suitable alternative. Ideally, the new instructions would also work on all systems whereapt-keyused to work. Thank you!My initial testing with this has not worked well so far
$ curl -fsS -o - "http://keyserver.ubuntu.com/pks/lookup?op=get&search=0xC99B11DEB97541F0" | gpg --dearmor | sudo tee /usr/share/keyrings/gh-archive-keyring.gpg $ echo "deb [arch=amd64 signed-by=/usr/share/keyrings/gh-archive-keyring.gpg] https://cli.github.com/packages bullseye main" | sudo tee /etc/apt/sources.list.d/gh.list
sudo apt updateoutputsErr:2 https://cli.github.com/packages bullseye InRelease The following signatures couldn't be verified because the public key is not available: NO_PUBKEY C99B11DEB97541F0This worked for me:
If you've been trying this some time, first delete the key from the root user's keyring in the two places you might find it:
# if $ sudo gpg -k /root/.gnupg/pubring.kbx ------------------------ pub rsa3072 2020-09-02 [SC] [expires: 2022-09-02] 2CA32056ED206CB81F44A8CAC99B11DEB97541F0 uid [ unknown] Nate Smith <[email protected]> sub rsa3072 2020-09-02 [E] [expires: 2022-09-02] # then $ sudo gpg --delete-keys 2CA32056ED206CB81F44A8CAC99B11DEB97541F0 gpg (GnuPG) 2.2.27; Copyright (C) 2021 Free Software Foundation, Inc. This is free software: you are free to change and redistribute it. There is NO WARRANTY, to the extent permitted by law. pub rsa3072/C99B11DEB97541F0 2020-09-02 Nate Smith <[email protected]> Delete this key from the keyring? (y/N) y # and $ keyfile=/usr/share/keyrings/gh-archive-keyring.gpg; if [ -f $keyfile ]; then sudo rm $keyfile; fiThen download the key to the keyring
$ sudo gpg --no-default-keyring --keyring /usr/share/keyrings/gh-archive-keyring.gpg --keyserver keyserver.ubuntu.com --search-keys C99B11DEB97541F0 gpg: keybox '/usr/share/keyrings/gh-archive-keyring.gpg' created gpg: data source: http://162.213.33.9:11371 (1) Nate Smith <[email protected]> 3072 bit RSA key C99B11DEB97541F0, created: 2020-09-02 Keys 1-1 of 1 for "C99B11DEB97541F0". Enter number(s), N)ext, or Q)uit > 1 gpg: key C99B11DEB97541F0: public key "Nate Smith <[email protected]>" imported gpg: Total number processed: 1 gpg: imported: 1Note: I learned this command from this online tutorial.
Add the signed entry to apt's sources
$ echo "deb [arch=amd64 signed-by=/usr/share/keyrings/gh-archive-keyring.gpg] https://cli.github.com/packages bullseye main" | sudo tee /etc/apt/sources.list.d/gh.listNote: I think you can replace
bullseyewith the distro installed on your machineUpdate the apt configuration
$ sudo apt update Hit:1 https://apt.repos.intel.com/oneapi all InRelease Get:2 https://cli.github.com/packages bullseye InRelease [3,747 B] Hit:3 http://security.debian.org/debian-security bullseye-security InRelease Hit:4 http://deb.debian.org/debian bullseye InRelease Get:5 https://cli.github.com/packages bullseye/main amd64 Packages [338 B] Fetched 338 B in 1s (411 B/s) Reading package lists... Done Building dependency tree... Done Reading state information... Done All packages are up to date.I'm using Debian testing and would hope this also works for other apt-based distros with the appropriate modifications to the apt sources
I am aware this method works on most distributions. However, the issue is that this method isn't universal as it does not work on WSL.
You get an error along the lines ofgpg: failed to create temporary file '/root/.gnupg/.#lk0x000055999c2c7bd0.Lenovo-G480.546': No such file or directory gpg: connecting dirmngr at '/root/.gnupg/S.dirmngr' failed: No such file or directory gpg: error searching keyserver: No dirmngr gpg: keyserver search failed: No dirmngr
See: microsoft/WSL#3286
I also had the dirmngr problem on Debian and think it was because
/root/.gnupgdidn't exist.
I reproduced the problem on WSL2 Debian Bullseye (which might be new enough to not have the bug found in the issue you linked) by doing$ sudo mv /root/.gnupg /root/somethingand then trying to download the key.To fix the problem, I ran
$ sudo dirmngr, which sets up/root/.gnupg, and then I downloaded the key without any problem.
I think you can also run$ sudo gpgto do the same.
The installation docs apt based systems includes an apt-key command: https://github.com/cli/cli/blob/trunk/docs/install_linux.md#debian-ubuntu-linux-apt
Running the recommended command results in the following warning:
The docs should probably be updated.