Opened 5 years ago

Closed 5 years ago

#1431 closed defect (worksforme)

Keys on debian repo kytv

Reported by: Eche|on Owned by: Eche|on
Priority: minor Milestone: 0.9.18
Component: www/debianrepo Version: 0.9.17
Keywords: Cc:
Parent Tickets: Sensitive: no

Description

Hi!

On a new user checking the install chain, issues do appear:

  1. the key noted on webpage to manual install is named not unque enough. Will break others maybe, rename the key to i2p.repo.key or something like I2P
  2. The key noted on geti2p to install manual is not the key with which i2p-keyring is signed with, apt-get will throw a error.

Please check this.

https://geti2p.net/_static/debian-repo.pub

echelon

Subtickets

Change History (3)

comment:1 in reply to:  description Changed 5 years ago by killyourtv

Component: package/debianwww/debianrepo
Owner: changed from killyourtv to Eche|on
Status: newassigned

Replying to echelon:

Hi!

On a new user checking the install chain, issues do appear:

  1. the key noted on webpage to manual install is named not unque enough. Will break others maybe, rename the key to i2p.repo.key or something like I2P

This is a simple change on the website. Since it harms nothing I can check it in.

  1. The key noted on geti2p to install manual is not the key with which i2p-keyring is signed with, apt-get will throw a error.

Please check this.

I don't understand what the problem is supposed to be. That is certainly the key that the repository is signed with. The i2p-keyring key is signed by that key (it's self-signed) and it's also signed by me. Ref:

$ dpkg -L i2p-keyring
/.
/usr
/usr/share
/usr/share/keyrings
/usr/share/keyrings/i2p-archive-removed-keys.gpg
/usr/share/keyrings/i2p-archive-keyring.gpg
/usr/share/doc
/usr/share/doc/i2p-keyring
/usr/share/doc/i2p-keyring/copyright
/usr/share/doc/i2p-keyring/changelog.gz


$ LC_ALL=C gpg -v /usr/share/keyrings/i2p-archive-keyring.gpg
pub  4096R/0x67ECE5605BCF1346 2013-10-10 I2P Debian Package Repository <killyourtv@i2pmail.org>
sig        0x67ECE5605BCF1346 2014-09-25   [selfsig]
gpg: NOTE: signature key 0xABE0C319DF0A0A1A expired Mon Nov  3 23:42:43 2014 EET
sig        0xABE0C319DF0A0A1A 2013-10-12   Kill Your TV <killyourtv@mail.i2p>
sig        0x67ECE5605BCF1346 2013-10-10   [selfsig]
sig        0xD82FE03CC55BCFE3 2014-02-21   [User ID not found]
sig        0x442907B588DFC457 2014-05-18   [User ID not found]
sig        0xF2EF2F47069E8B8F 2014-05-18   [User ID not found]
sig        0xF2EF2F47069E8B8F 2014-05-18   [User ID not found]
sig        0x2AD3ED43E7DB158F 2014-05-24   [User ID not found]
sig        0x5D70D2EBCAD2C9E6 2014-05-24   [User ID not found]
sig        0x3A2FD89479A7C4C1 2014-08-12   [User ID not found]
sub  4096R/0xD241CEBF3CAB5E06 2014-03-21 [expires: 2015-10-20]
sig        0x67ECE5605BCF1346 2014-09-25   [keybind]



$ LC_ALL=C wget https://geti2p.net/_static/debian-repo.pub
converted 'https://geti2p.net/_static/debian-repo.pub' (ANSI_X3.4-1968) -> 'https://geti2p.net/_static/debian-repo.pub' (UTF-8)
--2014-12-28 15:51:48--  https://geti2p.net/_static/debian-repo.pub
Resolving geti2p.net (geti2p.net)... 2a02:180:1:1:2456:6542:1101:1010, 91.143.92.136
Connecting to geti2p.net (geti2p.net)|2a02:180:1:1:2456:6542:1101:1010|:443... connected.
HTTP request sent, awaiting response... 200 OK
Length: 9127 (8.9K) [application/octet-stream]
Saving to: 'debian-repo.pub'

debian-repo.pub                                                     100%[=====================================================================================================================================================================>]   8.91K  --.-KB/s   in 0.007s 

2014-12-28 15:51:48 (1.21 MB/s) - 'debian-repo.pub' saved [9127/9127]



$ gpg -v debian-repo.pub 
pub  4096R/0x67ECE5605BCF1346 2013-10-10 I2P Debian Package Repository <killyourtv@i2pmail.org>
sig        0x67ECE5605BCF1346 2014-09-25   [selfsig]
gpg: NOTE: signature key 0xABE0C319DF0A0A1A expired ma  3. marraskuuta 2014 23.42.43 EET
sig        0xABE0C319DF0A0A1A 2013-10-12   Kill Your TV <killyourtv@mail.i2p>
sig        0x67ECE5605BCF1346 2013-10-10   [selfsig]
sig        0xD82FE03CC55BCFE3 2014-02-21   [User ID not found]
sig        0x442907B588DFC457 2014-05-18   [User ID not found]
sig        0xF2EF2F47069E8B8F 2014-05-18   [User ID not found]
sig        0xF2EF2F47069E8B8F 2014-05-18   [User ID not found]
sig        0x2AD3ED43E7DB158F 2014-05-24   [User ID not found]
sig        0x5D70D2EBCAD2C9E6 2014-05-24   [User ID not found]
sig        0x3A2FD89479A7C4C1 2014-08-12   [User ID not found]
sub  4096R/0xD241CEBF3CAB5E06 2014-03-21 [expires: 2015-10-20]
sig        0x67ECE5605BCF1346 2014-09-25   [keybind]

$ LC_ALL=C wget http://deb.i2p2.no/dists/wheezy/Release.gpg
converted 'http://deb.i2p2.no/dists/wheezy/Release.gpg' (ANSI_X3.4-1968) -> 'http://deb.i2p2.no/dists/wheezy/Release.gpg' (UTF-8)
--2014-12-28 15:54:03--  http://deb.i2p2.no/dists/wheezy/Release.gpg
Resolving deb.i2p2.no (deb.i2p2.no)... 193.150.121.69
Connecting to deb.i2p2.no (deb.i2p2.no)|193.150.121.69|:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 836
Saving to: 'Release.gpg'

Release.gpg                                                         100%[=====================================================================================================================================================================>]     836  --.-KB/s   in 0s     

2014-12-28 15:54:03 (78.9 MB/s) - 'Release.gpg' saved [836/836]

$ LC_ALL=C wget http://deb.i2p2.no/dists/wheezy/Release
converted 'http://deb.i2p2.no/dists/wheezy/Release' (ANSI_X3.4-1968) -> 'http://deb.i2p2.no/dists/wheezy/Release' (UTF-8)
--2014-12-28 15:54:10--  http://deb.i2p2.no/dists/wheezy/Release
Resolving deb.i2p2.no (deb.i2p2.no)... 193.150.121.69
Connecting to deb.i2p2.no (deb.i2p2.no)|193.150.121.69|:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 19028 (19K)
Saving to: 'Release'

Release                                                             100%[=====================================================================================================================================================================>]  18.58K  --.-KB/s   in 0.04s  

2014-12-28 15:54:10 (479 KB/s) - 'Release' saved [19028/19028]

$ LC_ALL=C gpg --verify Release.gpg Release
gpg: Signature made Thu Dec 18 13:48:38 2014 EET
gpg:                using RSA key 0x67ECE5605BCF1346
gpg: Good signature from "I2P Debian Package Repository <killyourtv@i2pmail.org>"

https://geti2p.net/_static/debian-repo.pub

As you can see above, the key in all of these is the same: 0x67ECE5605BCF1346. So what is the problem supposed to be here?

comment:2 Changed 5 years ago by killyourtv

Note: I have renamed the key on the website, but I reassigned it back to you to explain what the problem is with number 2 in the OP since I don't understand it.

comment:3 Changed 5 years ago by killyourtv

Resolution: worksforme
Status: assignedclosed

I'm assuming this was user error. Surely if there really was a problem with the key it would have been reported long ago, at least at some point since October 2013 when the repository was set up.

Note: See TracTickets for help on using tickets.