[tor-relays] EXPKEYSIG when running 'apt update'

Imre Jonk imre at imrejonk.nl
Fri Jun 17 18:39:45 UTC 2022


On Tue, 14 Jun 2022 19:19:54 +0200
Peter Gerber <tor-lists at arbitrary.ch> wrote:

> Looks like the expiration date on the key was changed and the package
> deb.torproject.org-keyring only updates that key in
> /usr/share/keyrings/. I can't but wonder if everyone that doesn't
> have a signed-by is affected, which must be quite a few.

Yeah I had the public signing key in both /etc/apt/trusted.gpg.d and
/usr/share/keyrings. I had to manually update the key in
/usr/share/keyrings/tor-archive-keyring.gpg as that file was referenced
by my sources.list file. Not sure how it ended up in two places. Thanks
for pointing this out!
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 833 bytes
Desc: OpenPGP digital signature
URL: <http://lists.torproject.org/pipermail/tor-relays/attachments/20220617/8c41ba7c/attachment.sig>


More information about the tor-relays mailing list