Skip to content

ubuntu public key unavailable #5810

Description

@DrPyser

Describe the feature or problem you’d like to solve

I'm trying to install github cli on ubuntu following the instructions, but apt can't seem to find and validate the public key used to sign the package.

Err:1 https://cli.github.com/packages stable InRelease
  The following signatures couldn't be verified because the public key is not available: NO_PUBKEY C99B11DEB97541F0
[...]
W: GPG error: https://cli.github.com/packages stable InRelease: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY C99B11DEB97541F0

It seems to be missing from keyserver.ubuntu.com:
https://keyserver.ubuntu.com/pks/lookup?search=C99B11DEB97541F0&op=hget

Proposed solution

Add public key to keyserver.ubuntu.com or update public key used to sign package.

Activity

  1. mislav commented on Jun 18, 2022

    @mislav
    Contributor

    Thanks for reporting. What is your Ubuntu version and have you followed our installation instructions? If so, is there a "signed-by" directive in "sources.list" file for our package repository?

  2. DrPyser commented on Jun 18, 2022

    @DrPyser
    Author

    Hi! Its Ubuntu 20.04. Yes, I've followed the instructions and there's the "signed-by" directive in the sources.

  3. added
    bugSomething isn't working
    priority-1Affects a large population and inhibits work
    and removed
    enhancementa request to improve CLI
    on Jun 20, 2022
  4. mislav commented on Jun 20, 2022

    @mislav
    Contributor

    Thanks for confirming. I thought that a locally downloaded key (pointed to by signed-by) would alleviate the need for the public key to be present in the keyserver. At least, that's how it seemed to work since we introduced a change to distance ourselves from keyserver: #3672

    Can you check that everyone has read (r) privileges to the keyring file?

    ls -l /usr/share/keyrings/githubcli-archive-keyring.gpg
    

    If not, try to add read privileges for everyone:

    sudo chmod go+r /usr/share/keyrings/githubcli-archive-keyring.gpg
    
  5. mislav commented on Jun 22, 2022

    @mislav
    Contributor

    @DrPyser ☝️ If you could check the permissions for us, that would be great. Thank you!

  6. DrPyser commented on Jun 22, 2022

    @DrPyser
    Author

    @mislav Yes, sorry for the late response. You're right, was missing world readable permissions.

  7. mislav commented on Jun 23, 2022

    @mislav
    Contributor

    @DrPyser Thank you for confirming! We have modified our installation instructions to fix the permissions issue when setting up our package repository 👍

  8. DrPyser commented on Jun 23, 2022

    @DrPyser
    Author

    Thank you!

  9. mjohngreene commented on Sep 7, 2022

    @mjohngreene

    I have this same problem running an update. The suggested change to give all users read - ie,

    $ ls -l /usr/share/keyrings/githubcli-archive-keyring.gpg          
    -rw-r--r-- 1 root root 1795 Nov 15  2021 /usr/share/keyrings/githubcli-archive-keyring.gpg
    

    does not appear to change anything.

  10. gadfort commented on Sep 7, 2022

    @gadfort

    @mjohngreene I also ran into this a few minutes ago. The install website says they changed the key recently and to follow their instructions: https://github.com/cli/cli/blob/trunk/docs/install_linux.md#debian-ubuntu-linux-raspberry-pi-os-apt
    Once I reran this (on Ubuntu) the error went away.

  11. mjohngreene commented on Sep 7, 2022

    @mjohngreene

    You're a champ, @arlpetergadfort! Cleared it right up. Thanks for the assist.

  12. burkettttt commented on Sep 7, 2022

    @burkettttt

    Followed directions in install_linux.md above and get the following:
    W: An error occurred during the signature verification. The repository is not updated and the previous index files will be used. GPG error: https://cli.github.com/packages focal InRelease: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 23F3D4EA75716059
    W: Failed to fetch https://cli.github.com/packages/dists/focal/InRelease The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 23F3D4EA75716059
    W: Some index files failed to download. They have been ignored, or old ones used instead.

    This is an improvement over the list I was receiving before doing install_linux.md, so progress is being made.

    cat /etc/os*
    NAME="Ubuntu"
    VERSION="20.04.5 LTS (Focal Fossa)"
    ID=ubuntu
    ID_LIKE=debian
    PRETTY_NAME="Ubuntu 20.04.5 LTS"
    VERSION_ID="20.04"
    HOME_URL="https://www.ubuntu.com/"
    SUPPORT_URL="https://help.ubuntu.com/"
    BUG_REPORT_URL="https://bugs.launchpad.net/ubuntu/"
    PRIVACY_POLICY_URL="https://www.ubuntu.com/legal/terms-and-policies/privacy-policy"
    VERSION_CODENAME=focal
    UBUNTU_CODENAME=focal

  13. daveyarwood commented on Sep 7, 2022

    @daveyarwood

    I'm also still having the same issue even after following the instructions linked above:

    W: An error occurred during the signature verification. The repository is not updated and the previous index files will be used. GPG error: https://cli.github.com/packages focal InRelease: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 23F3D4EA75716059
    W: Failed to fetch https://cli.github.com/packages/dists/focal/InRelease The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 23F3D4EA75716059
    W: Some index files failed to download. They have been ignored, or old ones used instead.

    Note that 23F3D4EA75716059 is the GPG signing key that those instructions say is the correct one, however the issue persists. Did the key change again after that?

    (I'm also using Ubuntu 20.04. I was able to successfully install the latest GitHub CLI version, 2.15.0, using the instructions above, however, I'm still getting this warning whenever I run apt update.)

  14. code-chimp commented on Sep 8, 2022

    @code-chimp

    I am currently running KDE Neon (20.04) and had to do the following (note: the first two lines were undoing the previous attempt to use the new accepted method in the docs):

    <removed by admin>
    

    I have not run the release upgrade to 22.04 yet, so this may just be for the last LTS, but I am now able to install/update gh without any errors.

    cat /etc/os*
    NAME="KDE neon"
    VERSION="5.25"
    ID=neon
    ID_LIKE="ubuntu debian"
    PRETTY_NAME="KDE neon User - 5.25"
    VARIANT="User Edition"
    VARIANT_ID=user
    VERSION_ID="20.04"
    HOME_URL="https://neon.kde.org/"
    SUPPORT_URL="https://neon.kde.org/"
    BUG_REPORT_URL="https://bugs.kde.org/"
    LOGO=start-here-kde-neon
    PRIVACY_POLICY_URL="https://www.ubuntu.com/legal/terms-and-policies/privacy-policy"
    VERSION_CODENAME=focal
    UBUNTU_CODENAME=focal
    
  15. daveyarwood commented on Sep 8, 2022

    @daveyarwood

    The command above worked for me! The warning I posted above is gone now when I run apt update.

    Thanks @code-chimp !

  16. insidemordecai commented on Sep 10, 2022

    @insidemordecai

    Had the same issue on Fedora 36 and most of the suggestions didn't work even after changing some commands to their Fedora equivalents, opted to dnf remove gh to allow other updates to be installed and reinstalled gh using the first option in the install_linux.md file

    Bit of a dodgy workaround but it worked for me and I did not have to authenticate gh again

  17. mohammad-quanit commented on Sep 25, 2022

    @mohammad-quanit

    Thanks alot @arlpetergadfort for sharing this. It solves in mint as well.

  18. tlnd-tjullien commented on Sep 26, 2022

    @tlnd-tjullien

    I had this issue, and the install instructions have another fix: redownload the GPG signing key.

    I just extracted the instructions from the doc, and it fixed the issue for me:

    curl -fsSL https://cli.github.com/packages/githubcli-archive-keyring.gpg | sudo dd of=/usr/share/keyrings/githubcli-archive-keyring.gpg \
    && sudo chmod go+r /usr/share/keyrings/githubcli-archive-keyring.gpg
    
  19. christofmuc commented on Sep 27, 2022

    @christofmuc

    @tlnd-tjullien Thank you, that did it for me! Running the commands from code-chimp alone wasn't enough.

  20. mislav commented on Sep 27, 2022

    @mislav
    Contributor

    Thanks everyone for sharing your solutions!

    Simply following our official installation instructions should always be enough to set up our package repository, even just for refreshing the key https://github.com/cli/cli/blob/trunk/docs/install_linux.md#debian-ubuntu-linux-raspberry-pi-os-apt

    I have removed previous suggestions to use keyserver and apt-add-repository because those tools cause problems and confusion for some people, plus the latter is deprecated in Ubuntu.

  21. locked as resolved and limited conversation to collaborators on Sep 27, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingpackagingpriority-1Affects a large population and inhibits work

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions