Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #185796 > unrolled thread
| Started by | Dan Norton <dnorton@mindspring.com> |
|---|---|
| First post | 2017-08-23 23:10 +0200 |
| Last post | 2017-08-24 18:20 +0200 |
| Articles | 9 — 3 participants |
Back to article view | Back to linux.debian.user
Public Key Dan Norton <dnorton@mindspring.com> - 2017-08-23 23:10 +0200
Re: Public Key Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-24 01:30 +0200
Re: Public Key Dan Norton <dnorton@mindspring.com> - 2017-08-24 02:40 +0200
Re: Public Key Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-24 03:00 +0200
Re: Public Key Dan Norton <dnorton@mindspring.com> - 2017-08-24 03:50 +0200
Re: Public Key Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-24 04:10 +0200
Re: Public Key Greg Wooledge <wooledg@eeg.ccf.org> - 2017-08-24 14:00 +0200
Re: Public Key Dan Norton <dnorton@mindspring.com> - 2017-08-24 17:20 +0200
Re: Public Key Mario Castelán Castro <marioxcc.MT@yandex.com> - 2017-08-24 18:20 +0200
| From | Dan Norton <dnorton@mindspring.com> |
|---|---|
| Date | 2017-08-23 23:10 +0200 |
| Subject | Public Key |
| Message-ID | <uhL4u-5FB-21@gated-at.bofh.it> |
[Multipart message — attachments visible in raw view] — view raw
#1 SMP Debian 3.16.43-2+deb8u2 (2017-06-26)
is on my desktop. In the process of installing borg from:
https://github.com/borgbackup/borg/releases
I have downloaded borg-linux64 and borg-linux64.asc.
From README.txt, there are instructions for verifying the download:
[...]
To check the GPG signature, download both the binary and the corresponding
*.asc file and then (on the shell) type, e.g.:
gpg --verify borg-linux64.asc borg-linux64
The files are signed by:
Thomas Waldmann <tw@waldmann-edv.de>
GPG key fingerprint: 6D5B EF9A DD20 7580 5747 B70F 9F88 FB52 FAF7 B393
[...]
and after several attempts to add this key and getting:
gpg: no valid OpenPGP data found.
I created borg-linux64.gpg containing the one-liner:
6D5BEF9ADD2075805747B70F9F88FB52FAF7B393
and got past "no valid" by doing (AFAICR):
sudo apt-key add borg-linux64.gpg
If nothing is amiss so far (a big if), the problem now is:
$ gpg --verify borg-linux64.asc borg-linux64
gpg: Signature made Sun 23 Jul 2017 07:23:38 PM EDT using RSA key ID
51F78E01
gpg: Can't check signature: public key not found
How to get the public key?
Thanks, - Dan
[toc] | [next] | [standalone]
| From | Mario Castelán Castro <marioxcc.MT@yandex.com> |
|---|---|
| Date | 2017-08-24 01:30 +0200 |
| Message-ID | <uhNfY-6XI-23@gated-at.bofh.it> |
| In reply to | #185796 |
[Multipart message — attachments visible in raw view] — view raw
On 23/08/17 15:11, Dan Norton wrote: > #1 SMP Debian 3.16.43-2+deb8u2 (2017-06-26) > is on my desktop. In the process of installing borg from: > > https://github.com/borgbackup/borg/releases You can install it easily in Debian. The package is called “borgbackup”. However, in Debian 9 it is an older version. If you want the latest version in Debian 9 you will have to install from the sources. > sudo apt-key add borg-linux64.gpg There is no reason to do this. You should not change the apt-get keys lightly. To install from source, there is no reason to add more trusted keys to apt-get. > If nothing is amiss so far (a big if), the problem now is: > > $ gpg --verify borg-linux64.asc borg-linux64 > gpg: Signature made Sun 23 Jul 2017 07:23:38 PM EDT using RSA key ID > 51F78E01 > gpg: Can't check signature: public key not found > > How to get the public key? See <https://borgbackup.readthedocs.io/en/stable/support.html#security-contact>. A key may claim to belong to X person, but you should not take the key's word for granted. You must verify that X person indeed owns that key. The best way to do this is that the person gives you face to face his gpg key. Second best is using the OpenPGP web of trust. In your case, probably neither option is possible, at least not immediately (joining the web of trust usually requires physically traveling to key signing parties, or something similar). The best you can do is to trust the key given by the official borg page. How do you know what is the official borg page? You should not trust a search engine for this, nor what the page itself claim, but you can trust the Debian developers (not because they are special, but because you are trusting them by using Debian). To see the home-page of a package in Debian, do as follows: $ apt-cache show borgbackup | grep ^Homepage Homepage: https://borgbackup.github.io/borgbackup/ After some clicks, starting in this page, you will end in the page I mentioned (which is <https://borgbackup.readthedocs.io/en/stable/support.html#security-contact>). After you have followed this procedure to obtain a fingerprint of the borg developer that signs the release, fetch the key with the following command (substitute FINGERPRINT with the actual fingerprint. You need not delete the spaces in the fingerprint, but do not delete the single quotation marks in the command): gpg --keyserver 'hkps://hkps.pool.sks-keyservers.net' --recv-key 'FINGERPRINT' Regards. -- Do not eat animals, respect them as you respect people. https://duckduckgo.com/?q=how+to+(become+OR+eat)+vegan
[toc] | [prev] | [next] | [standalone]
| From | Dan Norton <dnorton@mindspring.com> |
|---|---|
| Date | 2017-08-24 02:40 +0200 |
| Message-ID | <uhOlH-7C5-3@gated-at.bofh.it> |
| In reply to | #185799 |
On 08/23/2017 07:24 PM, Mario Castelán Castro wrote: > On 23/08/17 15:11, Dan Norton wrote: >> #1 SMP Debian 3.16.43-2+deb8u2 (2017-06-26) >> is on my desktop. In the process of installing borg from: >> >> https://github.com/borgbackup/borg/releases > You can install it easily in Debian. The package is called “borgbackup”. > However, in Debian 9 it is an older version. If you want the latest > version in Debian 9 you will have to install from the sources. I'm all for that, but unfortunately... $ apt-cache show borgbackup | grep ^Homepage E: No packages found Before posting I searched for borg and because nothing turned up I tried to install it another way. It's supposed to be a self-contained binary; the simplicity is appealing, but it's gotta be the real thing (not spoofed). > >> sudo apt-key add borg-linux64.gpg > There is no reason to do this. You should not change the apt-get keys > lightly. To install from source, there is no reason to add more trusted > keys to apt-get. Glad to learn this now. > >> If nothing is amiss so far (a big if), the problem now is: >> >> $ gpg --verify borg-linux64.asc borg-linux64 >> gpg: Signature made Sun 23 Jul 2017 07:23:38 PM EDT using RSA key ID >> 51F78E01 >> gpg: Can't check signature: public key not found >> >> How to get the public key? > See > <https://borgbackup.readthedocs.io/en/stable/support.html#security-contact>. > > A key may claim to belong to X person, but you should not take the key's > word for granted. You must verify that X person indeed owns that key. > The best way to do this is that the person gives you face to face his > gpg key. Second best is using the OpenPGP web of trust. > > In your case, probably neither option is possible, at least not > immediately (joining the web of trust usually requires physically > traveling to key signing parties, or something similar). The best you > can do is to trust the key given by the official borg page. > > How do you know what is the official borg page? You should not trust a > search engine for this, nor what the page itself claim, but you can > trust the Debian developers (not because they are special, but because > you are trusting them by using Debian). > > To see the home-page of a package in Debian, do as follows: > > $ apt-cache show borgbackup | grep ^Homepage > Homepage: https://borgbackup.github.io/borgbackup/ I like what you are saying. Now, if that package could be found we'd be in business. > > After some clicks, starting in this page, you will end in the page I > mentioned (which is > <https://borgbackup.readthedocs.io/en/stable/support.html#security-contact>). > > After you have followed this procedure to obtain a fingerprint of the > borg developer that signs the release, fetch the key with the following > command (substitute FINGERPRINT with the actual fingerprint. You need > not delete the spaces in the fingerprint, but do not delete the single > quotation marks in the command): > > gpg --keyserver 'hkps://hkps.pool.sks-keyservers.net' --recv-key > 'FINGERPRINT' How do we know about 'hkps://hkps.pool.sks-keyservers.net'? I tried the command... $ gpg --keyserver 'hkps://hkps.pool.sks-keyservers.net' --recv-key '<the key>' gpg: requesting key FAF7B393 from hkps server hkps.pool.sks-keyservers.net gpgkeys: HTTP fetch error 1: unsupported protocol gpg: no valid OpenPGP data found. gpg: Total number processed: 0 > > Regards. >
[toc] | [prev] | [next] | [standalone]
| From | Mario Castelán Castro <marioxcc.MT@yandex.com> |
|---|---|
| Date | 2017-08-24 03:00 +0200 |
| Message-ID | <uhOF4-7Ik-19@gated-at.bofh.it> |
| In reply to | #185800 |
[Multipart message — attachments visible in raw view] — view raw
On 23/08/17 19:34, Dan Norton wrote: > I'm all for that, but unfortunately... > $ apt-cache show borgbackup | grep ^Homepage > E: No packages found > > Before posting I searched for borg and because nothing turned up I tried > to install it another way. It's supposed to be a self-contained binary; > the simplicity is appealing, but it's gotta be the real thing (not > spoofed). “borgbackup” is in Debian 9. In Debian 8, borgbackup is available in backports. If you are using Debian 9 or higher, then you have a configuration problem because the package *is* there. >> After you have followed this procedure to obtain a fingerprint of the >> borg developer that signs the release, fetch the key with the following >> command (substitute FINGERPRINT with the actual fingerprint. You need >> not delete the spaces in the fingerprint, but do not delete the single >> quotation marks in the command): >> >> gpg --keyserver 'hkps://hkps.pool.sks-keyservers.net' --recv-key >> 'FINGERPRINT' > How do we know about 'hkps://hkps.pool.sks-keyservers.net'? I tried the > command... pool.sks-keyservers.net is a pool of servers of OpenPGP keys (OpenPGP is the format of keys and so on. GNU PG is the name of the program). Refer to <https://sks-keyservers.net/> for more information. Note that unlike fingerprints, the key server is not a security-critical component. All it does is to serve the *requested* key to GNU PG. If it served a key that was not the one requested, GNU PG would detect it. Though maybe denial of service attacks are possible by a malicious server, this is not something that should worry you too much. Always specify the full fingerprint when fetching keys. If you specify one of the shorter IDs (like “3003BEC50642D919” or “0642D919”) , the server could in principle generate a different key with the same ID and give that to you instead. > $ gpg --keyserver 'hkps://hkps.pool.sks-keyservers.net' --recv-key '<the > key>' > gpg: requesting key FAF7B393 from hkps server hkps.pool.sks-keyservers.net > gpgkeys: HTTP fetch error 1: unsupported protocol > gpg: no valid OpenPGP data found. > gpg: Total number processed: 0 I am not sure, but I think you are using a very old version of GNU PG that does not have support for HTTPS (HKPS is a protocol over HTTPS). The default version in Debian 9 (2.1.18) supports HKPS. But well, you can use plain HKP too: gpg --keyserver 'hkp://pool.sks-keyservers.net' --fingerprint 'FINGERPRINT' Make sure to use the whole fingerprint. It is a string of 40 hexadecimal digits, optionally interleaved with spaces, like this: E053 A25B CC30 2BBB 2DAD EC03 3003 BEC5 0642 D919 ----- When you reply in mailing list, please delete the parts of the quote that is no longer relevant. Otherwise most of your message is quotation and the conversation becomes hard to read. Regards. -- Do not eat animals, respect them as you respect people. https://duckduckgo.com/?q=how+to+(become+OR+eat)+vegan
[toc] | [prev] | [next] | [standalone]
| From | Dan Norton <dnorton@mindspring.com> |
|---|---|
| Date | 2017-08-24 03:50 +0200 |
| Message-ID | <uhPrt-8ei-53@gated-at.bofh.it> |
| In reply to | #185802 |
On 08/23/2017 08:53 PM, Mario Castelán Castro wrote: > If you are using Debian 9 or higher, then you have a configuration > problem because the package *is* there. Debian 8 is what I use. You must have snipped off that part of my post. > > I am not sure, but I think you are using a very old version of GNU PG > that does not have support for HTTPS (HKPS is a protocol over HTTPS). > The default version in Debian 9 (2.1.18) supports HKPS. > > But well, you can use plain HKP too: > > gpg --keyserver 'hkp://pool.sks-keyservers.net' --fingerprint 'FINGERPRINT' Hmm... $ sudo gpg --keyserver 'hkp://pool.sks-keyservers.net' --fingerprint '6D5B EF9A DD20 7580 5747 B70F 9F88 FB52 FAF7 B393' [sudo] password for dan: gpg: /root/.gnupg/trustdb.gpg: trustdb created gpg: error reading key: public key not found where have I seen that before? :-) Since borg is a self-contained binary, perhaps it does not need to be formally declared as a package in Debian 8. The problem is "how can one verify the download before moving it into /user/local/bin" as recommended by the author? https://borgbackup.readthedocs.io/en/stable/installation.html#pyinstaller-binary Verifying the download is the problem.
[toc] | [prev] | [next] | [standalone]
| From | Mario Castelán Castro <marioxcc.MT@yandex.com> |
|---|---|
| Date | 2017-08-24 04:10 +0200 |
| Message-ID | <uhPKO-aL-15@gated-at.bofh.it> |
| In reply to | #185803 |
[Multipart message — attachments visible in raw view] — view raw
On 23/08/17 20:52, Dan Norton wrote: > Debian 8 is what I use. You must have snipped off that part of my post. Right. You mentioned it in your very first post in this thread, but I skipped over it. My bad. > $ sudo gpg --keyserver 'hkp://pool.sks-keyservers.net' --fingerprint '6D5B EF9A DD20 7580 5747 B70F 9F88 FB52 FAF7 B393' > [sudo] password for dan: > gpg: /root/.gnupg/trustdb.gpg: trustdb created > gpg: error reading key: public key not found Ah, sorry. The correct command is “gpg --keyserver 'hkp://pool.sks-keyservers.net' --recv-keys 'FINGERPRINT'” (that is, replace “--fingerprint” with “--recv-keys”). > where have I seen that before? :-) > > Since borg is a self-contained binary, perhaps it does not need to be > formally declared as a package in Debian 8. There is no relation between “is self-contained binary” and whether it is in Debian. Again, borgbackup is available in Debian 8, but you have to enable backports. Moreover, Debian package borgbackups is not a self-contained binary. It uses the package manager to install the dependencies, just as any other package. It makes more sense this way when it is installed through the package manager. > The problem is "how can one > verify the download before moving it into /user/local/bin" as > recommended by the author? By the way, I recommend to use GNU Stow <https://www.gnu.org/software/stow/> when installing packages manually. It makes administration much easier when several packages are installed, and more so when upgrading or deleting packages. The point is to keep each “package” (roughly, any program distributed and installed as a whole; this is unrelated to packages as in apt-get) in a directory exclusively of its own use under /usr/local/stow, or any other directory. Then GNU Stow makes symbolic links from the directories where the system expect the package to be (e.g.: /usr/local/bin) to the place where the package is actually installed. This way you do not have to remember which files belong to which package when uninstalling a manually installed package. GNU Stow will also display a warning if you try to install (using GNU Stow) packages that have colliding files, instead of having them override eachother as would happen when doing “make install”. Regards. -- Do not eat animals, respect them as you respect people. https://duckduckgo.com/?q=how+to+(become+OR+eat)+vegan
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <wooledg@eeg.ccf.org> |
|---|---|
| Date | 2017-08-24 14:00 +0200 |
| Message-ID | <uhYXL-63x-5@gated-at.bofh.it> |
| In reply to | #185804 |
On Wed, Aug 23, 2017 at 09:07:02PM -0500, Mario Castelán Castro wrote: > There is no relation between “is self-contained binary” and whether it > is in Debian. Again, borgbackup is available in Debian 8, but you have > to enable backports. Which, for those who don't know, you do by following the instructions at <https://backports.debian.org/Instructions/>
[toc] | [prev] | [next] | [standalone]
| From | Dan Norton <dnorton@mindspring.com> |
|---|---|
| Date | 2017-08-24 17:20 +0200 |
| Message-ID | <ui25k-8gq-21@gated-at.bofh.it> |
| In reply to | #185804 |
[Multipart message — attachments visible in raw view] — view raw
On 08/23/2017 10:07 PM, Mario Castelán Castro wrote: > On 23/08/17 20:52, Dan Norton wrote: > >> Since borg is a self-contained binary, perhaps it does not need to be >> formally declared as a package in Debian 8. > There is no relation between “is self-contained binary” and whether it > is in Debian. Again, borgbackup is available in Debian 8, but you have > to enable backports. > > Moreover, Debian package borgbackups is not a self-contained binary. It > uses the package manager to install the dependencies, just as any other > package. It makes more sense this way when it is installed through the > package manager. OK, following instructions for installing backports (thanks, Greg) <https://backports.debian.org/Instructions/> I added the following to /etc/apt/sources.list : deb http://ftp.debian.org/debian jessie-backports main followed by... apt-get update apt-get -t jessie-backports install borgbackup and borg is installed. > > By the way, I recommend to use GNU Stow > <https://www.gnu.org/software/stow/> when installing packages manually. > It makes administration much easier when several packages are installed, > and more so when upgrading or deleting packages. > > The point is to keep each “package” (roughly, any program distributed > and installed as a whole; this is unrelated to packages as in apt-get) > in a directory exclusively of its own use under /usr/local/stow, or any > other directory. Then GNU Stow makes symbolic links from the directories > where the system expect the package to be (e.g.: /usr/local/bin) to the > place where the package is actually installed. This way you do not have > to remember which files belong to which package when uninstalling a > manually installed package. GNU Stow will also display a warning if you > try to install (using GNU Stow) packages that have colliding files, > instead of having them override eachother as would happen when doing > “make install”. > Oops - forgot to try GNU Stow. Another time maybe. Thank you, Mario, for your help. Great discussion. - Dan
[toc] | [prev] | [next] | [standalone]
| From | Mario Castelán Castro <marioxcc.MT@yandex.com> |
|---|---|
| Date | 2017-08-24 18:20 +0200 |
| Message-ID | <ui31n-pa-9@gated-at.bofh.it> |
| In reply to | #185834 |
[Multipart message — attachments visible in raw view] — view raw
On 24/08/17 10:21, Dan Norton wrote: > Oops - forgot to try GNU Stow. Another time maybe. In this case, you used the package manager, so there is no need for stow. GNU Stow is useful when installing manually, for example, when one compiles from source. > Thank you, Mario, for your help. Great discussion. No problem Dan. Glad to be of help. -- Do not eat animals, respect them as you respect people. https://duckduckgo.com/?q=how+to+(become+OR+eat)+vegan
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.user
csiph-web