Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #185796 > unrolled thread

Public Key

Started byDan Norton <dnorton@mindspring.com>
First post2017-08-23 23:10 +0200
Last post2017-08-24 18:20 +0200
Articles 9 — 3 participants

Back to article view | Back to linux.debian.user


Contents

  Public Key Dan Norton <dnorton@mindspring.com> - 2017-08-23 23:10 +0200
    Re: Public Key Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-24 01:30 +0200
      Re: Public Key Dan Norton <dnorton@mindspring.com> - 2017-08-24 02:40 +0200
        Re: Public Key Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-24 03:00 +0200
          Re: Public Key Dan Norton <dnorton@mindspring.com> - 2017-08-24 03:50 +0200
            Re: Public Key Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-24 04:10 +0200
              Re: Public Key Greg Wooledge <wooledg@eeg.ccf.org> - 2017-08-24 14:00 +0200
              Re: Public Key Dan Norton <dnorton@mindspring.com> - 2017-08-24 17:20 +0200
                Re: Public Key Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-24 18:20 +0200

#185796 — Public Key

FromDan Norton <dnorton@mindspring.com>
Date2017-08-23 23:10 +0200
SubjectPublic Key
Message-ID<uhL4u-5FB-21@gated-at.bofh.it>

[Multipart message — attachments visible in raw view] — view raw

#1 SMP Debian 3.16.43-2+deb8u2 (2017-06-26)
is on my desktop. In the process of installing borg from:

https://github.com/borgbackup/borg/releases

I have downloaded borg-linux64 and borg-linux64.asc.

 From README.txt, there are instructions for verifying the download:

[...]

To check the GPG signature, download both the binary and the corresponding
*.asc file and then (on the shell) type, e.g.:

     gpg --verify borg-linux64.asc borg-linux64

The files are signed by:

Thomas Waldmann <tw@waldmann-edv.de>
GPG key fingerprint: 6D5B EF9A DD20 7580 5747 B70F 9F88 FB52 FAF7 B393
[...]

and after several attempts to add this key and getting:

gpg: no valid OpenPGP data found.

I created borg-linux64.gpg containing the one-liner:

6D5BEF9ADD2075805747B70F9F88FB52FAF7B393

and got past "no valid" by doing (AFAICR):

sudo apt-key add borg-linux64.gpg

If nothing is amiss so far (a big if), the problem now is:

$ gpg --verify borg-linux64.asc borg-linux64
gpg: Signature made Sun 23 Jul 2017 07:23:38 PM EDT using RSA key ID 
51F78E01
gpg: Can't check signature: public key not found

How to get the public key?

Thanks,  - Dan


[toc] | [next] | [standalone]


#185799

FromMario Castelán Castro <marioxcc.MT@yandex.com>
Date2017-08-24 01:30 +0200
Message-ID<uhNfY-6XI-23@gated-at.bofh.it>
In reply to#185796

[Multipart message — attachments visible in raw view] — view raw

On 23/08/17 15:11, Dan Norton wrote:
> #1 SMP Debian 3.16.43-2+deb8u2 (2017-06-26)
> is on my desktop. In the process of installing borg from:
> 
> https://github.com/borgbackup/borg/releases

You can install it easily in Debian. The package is called “borgbackup”.
However, in Debian 9 it is an older version. If you want the latest
version in Debian 9 you will have to install from the sources.

> sudo apt-key add borg-linux64.gpg

There is no reason to do this. You should not change the apt-get keys
lightly. To install from source, there is no reason to add more trusted
keys to apt-get.

> If nothing is amiss so far (a big if), the problem now is:
> 
> $ gpg --verify borg-linux64.asc borg-linux64
> gpg: Signature made Sun 23 Jul 2017 07:23:38 PM EDT using RSA key ID
> 51F78E01
> gpg: Can't check signature: public key not found
> 
> How to get the public key?

See
<https://borgbackup.readthedocs.io/en/stable/support.html#security-contact>.

A key may claim to belong to X person, but you should not take the key's
word for granted. You must verify that X person indeed owns that key.
The best way to do this is that the person gives you face to face his
gpg key. Second best is using the OpenPGP web of trust.

In your case, probably neither option is possible, at least not
immediately (joining the web of trust usually requires physically
traveling to key signing parties, or something similar). The best you
can do is to trust the key given by the official borg page.

How do you know what is the official borg page? You should not trust a
search engine for this, nor what the page itself claim, but you can
trust the Debian developers (not because they are special, but because
you are trusting them by using Debian).

To see the home-page of a package in Debian, do as follows:

$ apt-cache show borgbackup | grep ^Homepage
Homepage: https://borgbackup.github.io/borgbackup/

After some clicks, starting in this page, you will end in the page I
mentioned (which is
<https://borgbackup.readthedocs.io/en/stable/support.html#security-contact>).

After you have followed this procedure to obtain a fingerprint of the
borg developer that signs the release, fetch the key with the following
command (substitute FINGERPRINT with the actual fingerprint. You need
not delete the spaces in the fingerprint, but do not delete the single
quotation marks in the command):

gpg --keyserver 'hkps://hkps.pool.sks-keyservers.net' --recv-key
'FINGERPRINT'

Regards.

-- 
Do not eat animals, respect them as you respect people.
https://duckduckgo.com/?q=how+to+(become+OR+eat)+vegan

[toc] | [prev] | [next] | [standalone]


#185800

FromDan Norton <dnorton@mindspring.com>
Date2017-08-24 02:40 +0200
Message-ID<uhOlH-7C5-3@gated-at.bofh.it>
In reply to#185799

On 08/23/2017 07:24 PM, Mario Castelán Castro wrote:
> On 23/08/17 15:11, Dan Norton wrote:
>> #1 SMP Debian 3.16.43-2+deb8u2 (2017-06-26)
>> is on my desktop. In the process of installing borg from:
>>
>> https://github.com/borgbackup/borg/releases
> You can install it easily in Debian. The package is called “borgbackup”.
> However, in Debian 9 it is an older version. If you want the latest
> version in Debian 9 you will have to install from the sources.
I'm all for that, but unfortunately...
$ apt-cache show borgbackup | grep ^Homepage
E: No packages found

Before posting I searched for borg and because nothing turned up I tried 
to install it another way. It's supposed to be a self-contained binary; 
the simplicity is appealing, but it's gotta be the real thing (not 
spoofed).
>
>> sudo apt-key add borg-linux64.gpg
> There is no reason to do this. You should not change the apt-get keys
> lightly. To install from source, there is no reason to add more trusted
> keys to apt-get.
Glad to learn this now.
>
>> If nothing is amiss so far (a big if), the problem now is:
>>
>> $ gpg --verify borg-linux64.asc borg-linux64
>> gpg: Signature made Sun 23 Jul 2017 07:23:38 PM EDT using RSA key ID
>> 51F78E01
>> gpg: Can't check signature: public key not found
>>
>> How to get the public key?
> See
> <https://borgbackup.readthedocs.io/en/stable/support.html#security-contact>.
>
> A key may claim to belong to X person, but you should not take the key's
> word for granted. You must verify that X person indeed owns that key.
> The best way to do this is that the person gives you face to face his
> gpg key. Second best is using the OpenPGP web of trust.
>
> In your case, probably neither option is possible, at least not
> immediately (joining the web of trust usually requires physically
> traveling to key signing parties, or something similar). The best you
> can do is to trust the key given by the official borg page.
>
> How do you know what is the official borg page? You should not trust a
> search engine for this, nor what the page itself claim, but you can
> trust the Debian developers (not because they are special, but because
> you are trusting them by using Debian).
>
> To see the home-page of a package in Debian, do as follows:
>
> $ apt-cache show borgbackup | grep ^Homepage
> Homepage: https://borgbackup.github.io/borgbackup/
I like what you are saying. Now, if that package could be found we'd be 
in business.
>
> After some clicks, starting in this page, you will end in the page I
> mentioned (which is
> <https://borgbackup.readthedocs.io/en/stable/support.html#security-contact>).
>
> After you have followed this procedure to obtain a fingerprint of the
> borg developer that signs the release, fetch the key with the following
> command (substitute FINGERPRINT with the actual fingerprint. You need
> not delete the spaces in the fingerprint, but do not delete the single
> quotation marks in the command):
>
> gpg --keyserver 'hkps://hkps.pool.sks-keyservers.net' --recv-key
> 'FINGERPRINT'
How do we know about 'hkps://hkps.pool.sks-keyservers.net'? I tried the 
command...

$ gpg --keyserver 'hkps://hkps.pool.sks-keyservers.net' --recv-key '<the 
key>'
gpg: requesting key FAF7B393 from hkps server hkps.pool.sks-keyservers.net
gpgkeys: HTTP fetch error 1: unsupported protocol
gpg: no valid OpenPGP data found.
gpg: Total number processed: 0



>
> Regards.
>

[toc] | [prev] | [next] | [standalone]


#185802

FromMario Castelán Castro <marioxcc.MT@yandex.com>
Date2017-08-24 03:00 +0200
Message-ID<uhOF4-7Ik-19@gated-at.bofh.it>
In reply to#185800

[Multipart message — attachments visible in raw view] — view raw

On 23/08/17 19:34, Dan Norton wrote:
> I'm all for that, but unfortunately...
> $ apt-cache show borgbackup | grep ^Homepage
> E: No packages found
> 
> Before posting I searched for borg and because nothing turned up I tried
> to install it another way. It's supposed to be a self-contained binary;
> the simplicity is appealing, but it's gotta be the real thing (not
> spoofed).

“borgbackup” is in Debian 9. In Debian 8, borgbackup is available in
backports.

If you are using Debian 9 or higher, then you have a configuration
problem because the package *is* there.

>> After you have followed this procedure to obtain a fingerprint of the
>> borg developer that signs the release, fetch the key with the following
>> command (substitute FINGERPRINT with the actual fingerprint. You need
>> not delete the spaces in the fingerprint, but do not delete the single
>> quotation marks in the command):
>>
>> gpg --keyserver 'hkps://hkps.pool.sks-keyservers.net' --recv-key
>> 'FINGERPRINT'
> How do we know about 'hkps://hkps.pool.sks-keyservers.net'? I tried the
> command...

pool.sks-keyservers.net is a pool of servers of OpenPGP keys (OpenPGP is
the format of keys and so on. GNU PG is the name of the program). Refer
to <https://sks-keyservers.net/> for more information.

Note that unlike fingerprints, the key server is not a security-critical
component. All it does is to serve the *requested* key to GNU PG. If it
served a key that was not the one requested, GNU PG would detect it.
Though maybe denial of service attacks are possible by a malicious
server, this is not something that should worry you too much.

Always specify the full fingerprint when fetching keys. If you specify
one of the shorter IDs (like “3003BEC50642D919” or “0642D919”) , the
server could in principle generate a different key with the same ID and
give that to you instead.

> $ gpg --keyserver 'hkps://hkps.pool.sks-keyservers.net' --recv-key '<the
> key>'
> gpg: requesting key FAF7B393 from hkps server hkps.pool.sks-keyservers.net
> gpgkeys: HTTP fetch error 1: unsupported protocol
> gpg: no valid OpenPGP data found.
> gpg: Total number processed: 0

I am not sure, but I think you are using a very old version of GNU PG
that does not have support for HTTPS (HKPS is a protocol over HTTPS).
The default version in Debian 9 (2.1.18) supports HKPS.

But well, you can use plain HKP too:

gpg --keyserver 'hkp://pool.sks-keyservers.net' --fingerprint 'FINGERPRINT'

Make sure to use the whole fingerprint. It is a string of 40 hexadecimal
digits, optionally interleaved with spaces, like this:

E053 A25B CC30 2BBB 2DAD  EC03 3003 BEC5 0642 D919

-----
When you reply in mailing list, please delete the parts of the quote
that is no longer relevant. Otherwise most of your message is quotation
and the conversation becomes hard to read.

Regards.

-- 
Do not eat animals, respect them as you respect people.
https://duckduckgo.com/?q=how+to+(become+OR+eat)+vegan

[toc] | [prev] | [next] | [standalone]


#185803

FromDan Norton <dnorton@mindspring.com>
Date2017-08-24 03:50 +0200
Message-ID<uhPrt-8ei-53@gated-at.bofh.it>
In reply to#185802

On 08/23/2017 08:53 PM, Mario Castelán Castro wrote:
> If you are using Debian 9 or higher, then you have a configuration
> problem because the package *is* there.
Debian 8 is what I use. You must have snipped off that part of my post.

>
> I am not sure, but I think you are using a very old version of GNU PG
> that does not have support for HTTPS (HKPS is a protocol over HTTPS).
> The default version in Debian 9 (2.1.18) supports HKPS.
>
> But well, you can use plain HKP too:
>
> gpg --keyserver 'hkp://pool.sks-keyservers.net' --fingerprint 'FINGERPRINT'
Hmm...
$ sudo gpg --keyserver 'hkp://pool.sks-keyservers.net' --fingerprint 
'6D5B EF9A DD20 7580 5747 B70F 9F88 FB52 FAF7 B393'
[sudo] password for dan:
gpg: /root/.gnupg/trustdb.gpg: trustdb created
gpg: error reading key: public key not found

where have I seen that before? :-)

Since borg is a self-contained binary, perhaps it does not need to be 
formally declared as a package in Debian 8. The problem is "how can one 
verify the download before moving it into /user/local/bin" as 
recommended by the author?

https://borgbackup.readthedocs.io/en/stable/installation.html#pyinstaller-binary

Verifying the download is the problem.

[toc] | [prev] | [next] | [standalone]


#185804

FromMario Castelán Castro <marioxcc.MT@yandex.com>
Date2017-08-24 04:10 +0200
Message-ID<uhPKO-aL-15@gated-at.bofh.it>
In reply to#185803

[Multipart message — attachments visible in raw view] — view raw

On 23/08/17 20:52, Dan Norton wrote:
> Debian 8 is what I use. You must have snipped off that part of my post.

Right. You mentioned it in your very first post in this thread, but I
skipped over it. My bad.

> $ sudo gpg --keyserver 'hkp://pool.sks-keyservers.net' --fingerprint '6D5B EF9A DD20 7580 5747 B70F 9F88 FB52 FAF7 B393'
> [sudo] password for dan:
> gpg: /root/.gnupg/trustdb.gpg: trustdb created
> gpg: error reading key: public key not found 

Ah, sorry. The correct command is “gpg --keyserver
'hkp://pool.sks-keyservers.net' --recv-keys 'FINGERPRINT'” (that is,
replace “--fingerprint” with “--recv-keys”).

> where have I seen that before? :-)
> 
> Since borg is a self-contained binary, perhaps it does not need to be
> formally declared as a package in Debian 8.

There is no relation between “is self-contained binary” and whether it
is in Debian. Again, borgbackup is available in Debian 8, but you have
to enable backports.

Moreover, Debian package borgbackups is not a self-contained binary. It
uses the package manager to install the dependencies, just as any other
package. It makes more sense this way when it is installed through the
package manager.

> The problem is "how can one
> verify the download before moving it into /user/local/bin" as
> recommended by the author?

By the way, I recommend to use GNU Stow
<https://www.gnu.org/software/stow/> when installing packages manually.
It makes administration much easier when several packages are installed,
and more so when upgrading or deleting packages.

The point is to keep each “package” (roughly, any program distributed
and installed as a whole; this is unrelated to packages as in apt-get)
in a directory exclusively of its own use under /usr/local/stow, or any
other directory. Then GNU Stow makes symbolic links from the directories
where the system expect the package to be (e.g.: /usr/local/bin) to the
place where the package is actually installed. This way you do not have
to remember which files belong to which package when uninstalling a
manually installed package. GNU Stow will also display a warning if you
try to install (using GNU Stow) packages that have colliding files,
instead of having them override eachother as would happen when doing
“make install”.

Regards.

-- 
Do not eat animals, respect them as you respect people.
https://duckduckgo.com/?q=how+to+(become+OR+eat)+vegan

[toc] | [prev] | [next] | [standalone]


#185819

FromGreg Wooledge <wooledg@eeg.ccf.org>
Date2017-08-24 14:00 +0200
Message-ID<uhYXL-63x-5@gated-at.bofh.it>
In reply to#185804
On Wed, Aug 23, 2017 at 09:07:02PM -0500, Mario Castelán Castro wrote:
> There is no relation between “is self-contained binary” and whether it
> is in Debian. Again, borgbackup is available in Debian 8, but you have
> to enable backports.

Which, for those who don't know, you do by following the instructions
at <https://backports.debian.org/Instructions/>

[toc] | [prev] | [next] | [standalone]


#185834

FromDan Norton <dnorton@mindspring.com>
Date2017-08-24 17:20 +0200
Message-ID<ui25k-8gq-21@gated-at.bofh.it>
In reply to#185804

[Multipart message — attachments visible in raw view] — view raw

On 08/23/2017 10:07 PM, Mario Castelán Castro wrote:
> On 23/08/17 20:52, Dan Norton wrote:
>
>> Since borg is a self-contained binary, perhaps it does not need to be
>> formally declared as a package in Debian 8.
> There is no relation between “is self-contained binary” and whether it
> is in Debian. Again, borgbackup is available in Debian 8, but you have
> to enable backports.
>
> Moreover, Debian package borgbackups is not a self-contained binary. It
> uses the package manager to install the dependencies, just as any other
> package. It makes more sense this way when it is installed through the
> package manager.

OK, following instructions for installing backports (thanks, Greg)

<https://backports.debian.org/Instructions/>

I added the following to /etc/apt/sources.list :
deb http://ftp.debian.org/debian jessie-backports main

followed by...
apt-get update
apt-get -t jessie-backports install borgbackup

and borg is installed.

>
> By the way, I recommend to use GNU Stow
> <https://www.gnu.org/software/stow/> when installing packages manually.
> It makes administration much easier when several packages are installed,
> and more so when upgrading or deleting packages.
>
> The point is to keep each “package” (roughly, any program distributed
> and installed as a whole; this is unrelated to packages as in apt-get)
> in a directory exclusively of its own use under /usr/local/stow, or any
> other directory. Then GNU Stow makes symbolic links from the directories
> where the system expect the package to be (e.g.: /usr/local/bin) to the
> place where the package is actually installed. This way you do not have
> to remember which files belong to which package when uninstalling a
> manually installed package. GNU Stow will also display a warning if you
> try to install (using GNU Stow) packages that have colliding files,
> instead of having them override eachother as would happen when doing
> “make install”.
>
Oops - forgot to try GNU Stow. Another time maybe.

Thank you, Mario, for your help. Great discussion.

  - Dan

[toc] | [prev] | [next] | [standalone]


#185839

FromMario Castelán Castro <marioxcc.MT@yandex.com>
Date2017-08-24 18:20 +0200
Message-ID<ui31n-pa-9@gated-at.bofh.it>
In reply to#185834

[Multipart message — attachments visible in raw view] — view raw

On 24/08/17 10:21, Dan Norton wrote:
> Oops - forgot to try GNU Stow. Another time maybe.

In this case, you used the package manager, so there is no need for
stow. GNU Stow is useful when installing manually, for example, when one
compiles from source.

> Thank you, Mario, for your help. Great discussion.

No problem Dan. Glad to be of help.

-- 
Do not eat animals, respect them as you respect people.
https://duckduckgo.com/?q=how+to+(become+OR+eat)+vegan

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web