Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #245960 > unrolled thread

apt-key deprecation.

Started byErwan David <erwan@rail.eu.org>
First post2022-03-05 19:50 +0100
Last post2022-03-06 00:40 +0100
Articles 5 — 4 participants

Back to article view | Back to linux.debian.user


Contents

  apt-key deprecation. Erwan David <erwan@rail.eu.org> - 2022-03-05 19:50 +0100
    Re: apt-key deprecation. Cindy Sue Causey <butterflybytes@gmail.com> - 2022-03-05 20:10 +0100
      Re: apt-key deprecation. Erwan David <erwan@rail.eu.org> - 2022-03-05 20:40 +0100
        Re: apt-key deprecation. <tomas@tuxteam.de> - 2022-03-05 21:00 +0100
    Re: apt-key deprecation. Marcelo Laia <marcelolaia@gmail.com> - 2022-03-06 00:40 +0100

#245960 — apt-key deprecation.

FromErwan David <erwan@rail.eu.org>
Date2022-03-05 19:50 +0100
Subjectapt-key deprecation.
Message-ID<DXHDz-65yH-3@gated-at.bofh.it>
Hi,

When I update my packages I get the warning :

W: 
https://download.virtualbox.org/virtualbox/debian/dists/buster/InRelease: 
Key is stored in legacy trusted.gpg keyring (/etc/apt/trusted.gpg), see 
the DEPRECATION section in apt-key(8) for details.


I looked at section DEPRECATION in apt-key, but did not find how I can 
extract those keys from /etc/apt/trusted.gpg and put them in trusted.gpg.d


What would be the easier way ?

[toc] | [next] | [standalone]


#245961

FromCindy Sue Causey <butterflybytes@gmail.com>
Date2022-03-05 20:10 +0100
Message-ID<DXHWV-65UP-1@gated-at.bofh.it>
In reply to#245960
On 3/5/22, Erwan David <erwan@rail.eu.org> wrote:
> Hi,
>
> When I update my packages I get the warning :
>
> W:
> https://download.virtualbox.org/virtualbox/debian/dists/buster/InRelease:
> Key is stored in legacy trusted.gpg keyring (/etc/apt/trusted.gpg), see
> the DEPRECATION section in apt-key(8) for details.
>
> I looked at section DEPRECATION in apt-key, but did not find how I can
> extract those keys from /etc/apt/trusted.gpg and put them in trusted.gpg.d
>
> What would be the easier way ?


My apologies if you personally already know what I'm about to write.
Am still posting for potential newbies visiting the archives.

While you're waiting on the answer that corrects this, I needed to fix
two of mine, too. I took your query as my sign to follow through.
First up is this explanation that might easily play into what's going
on:

https://askubuntu.com/questions/1286545/what-commands-exactly-should-replace-the-deprecated-apt-key

Even if it's not directly related to the change that occurred in that
very recent Debian package upgrade, it's still important to always
have in mind. It's relevant because, however you and I and all others
affected correct this warning, we need to know that one factor is our
CHOICE as to how far we trust each affected repository. I hadn't
really thought that far ahead about it until seeing that in writing.

For me, I trust the two repositories involved and would grant them
wide open access. Someone else might be pulling from a repository that
allows all kinds of different Developers to add their packages into a
pool. That scenario should cause an admin to cherry pick each
package-specific key added after researching each single key for its
safety as new keys continue to appear over time.

Cindy :)
-- 
Talking Rock, Pickens County, Georgia, USA
* runs with birdseed *

[toc] | [prev] | [next] | [standalone]


#245963

FromErwan David <erwan@rail.eu.org>
Date2022-03-05 20:40 +0100
Message-ID<DXIpX-6643-1@gated-at.bofh.it>
In reply to#245961
Le 05/03/2022 à 20:04, Cindy Sue Causey a écrit :
> On 3/5/22, Erwan David <erwan@rail.eu.org> wrote:
>> Hi,
>>
>> When I update my packages I get the warning :
>>
>> W:
>> https://download.virtualbox.org/virtualbox/debian/dists/buster/InRelease:
>> Key is stored in legacy trusted.gpg keyring (/etc/apt/trusted.gpg), see
>> the DEPRECATION section in apt-key(8) for details.
>>
>> I looked at section DEPRECATION in apt-key, but did not find how I can
>> extract those keys from /etc/apt/trusted.gpg and put them in trusted.gpg.d
>>
>> What would be the easier way ?
>

Yes I already saw this but

1) How do I extract keys from /etc/apt/trusted.gpg ?

2) Can I completely remove the file once I have extracted all non-debian 
keys from it ?

Putting the key in another location and specifying where to llok for 
each repository does not work, because of packages which add their key 
in /etc/apt/trusted.gpg.d (one example is spotify, and I think micorsoft 
teams)

But my problem is with the lack of documentation for transitioning from 
old scheme to new one.

[toc] | [prev] | [next] | [standalone]


#245964

From<tomas@tuxteam.de>
Date2022-03-05 21:00 +0100
Message-ID<DXIJj-66am-1@gated-at.bofh.it>
In reply to#245963

[Multipart message — attachments visible in raw view] — view raw

On Sat, Mar 05, 2022 at 08:31:46PM +0100, Erwan David wrote:
> Le 05/03/2022 à 20:04, Cindy Sue Causey a écrit :
> > On 3/5/22, Erwan David <erwan@rail.eu.org> wrote:
> > > Hi,
> > > 
> > > When I update my packages I get the warning :
> > > 
> > > W:
> > > https://download.virtualbox.org/virtualbox/debian/dists/buster/InRelease:
> > > Key is stored in legacy trusted.gpg keyring (/etc/apt/trusted.gpg), see
> > > the DEPRECATION section in apt-key(8) for details.
> > > 
> > > I looked at section DEPRECATION in apt-key, but did not find how I can
> > > extract those keys from /etc/apt/trusted.gpg and put them in trusted.gpg.d
> > > 
> > > What would be the easier way ?
> > 
> 
> Yes I already saw this but
> 
> 1) How do I extract keys from /etc/apt/trusted.gpg ?

This is a gpg keyring. You can list the keys therein like so:

  gpg --list-keys --no-default-keyring --keyring /etc/apt/trusted.gpg

You can export some or all with --export; if you want them in
their ASCII "flavour", you also add --armor.

  gpg --armor --no-default-keyring --keyring /etc/apt/trusted.gpg --export dev@jitsi.org > keys.out

(where this `dev@jitsi.org' stands for one of the IDs you have
seen above, with --list).

As to your other questions... I'll leave them to those who know
more :)

Cheers
-- 
t

[toc] | [prev] | [next] | [standalone]


#245968

FromMarcelo Laia <marcelolaia@gmail.com>
Date2022-03-06 00:40 +0100
Message-ID<DXMad-68iC-3@gated-at.bofh.it>
In reply to#245960
> What would be the easier way ?

I did:

# curl https://www.virtualbox.org/download/oracle_vbox_2016.asc | gpg --dearmor > /usr/share/keyrings/virtualbox-keyring.gpg

$ sudoedit /etc/apt/sources.list.d/virtualbox.sources

And filled the file virtualbox.sources with:

Types: deb
URIs: https://download.virtualbox.org/virtualbox/debian
Suites: bullseye
Architectures: amd64
Components: contrib non-free
Signed-By: /usr/share/keyrings/virtualbox-keyring.gpg


I found help on [1] and [2].

1. https://wiki.debian.org/DebianRepository/UseThirdParty

2. https://unix.stackexchange.com/questions/332672/how-to-add-a-third-party-repo-and-key-in-debian/582853#582853

-- 
Marcelo

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web