Ad Widget

Collapse

This key is not certified with a trusted signature!

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • olga-
    Junior Member
    • Sep 2016
    • 2

    #1

    This key is not certified with a trusted signature!

    I' trying to clone zabbix repo for 3.2 branch using reprepro. And had no problems with 3.0 and older branches.

    gpg Release.gpg
    Detached signature.
    Please enter name of data file: Release
    gpg: Signature made Fri 16 Sep 2016 03:41:16 AM UTC using RSA key ID A14FE591
    gpg: Good signature from "Zabbix LLC <[email protected]>"
    gpg: WARNING: This key is not certified with a trusted signature!
    gpg: There is no indication that the signature belongs to the owner.

    But the keys itself are added:

    gpg --list-keys

    pub 2048R/A14FE591 2016-07-15
    uid Zabbix LLC <[email protected]>
    sub 2048R/E709712C 2016-07-15

    pub 1024D/79EA5ED4 2012-10-28
    uid Zabbix SIA <[email protected]>
    sub 1024g/7E1DEF85 2012-10-28

    But cannot update repository:

    reprepro -V update
    aptmethod got 'http://repo.zabbix.com/zabbix/3.2/debian/dists/wheezy/InRelease'
    ERROR: Condition 'D13D58E479EA5ED4' not fullfilled for './lists/zabbix-3%2E2_wheezy_InRelease'.
    Signatures in './lists/zabbix-3%2E2_wheezy_InRelease':
    'A1848F5352D022B9471D83D0082AB56BA14FE591' (signed 2016-09-16): valid
    Error: Not enough signatures found for remote repository zabbix-3.2 (http://repo.zabbix.com/zabbix/3.2/debian wheezy)!
    There have been errors!

    Any ideas?
  • olga-
    Junior Member
    • Sep 2016
    • 2

    #2
    Figured out the problem- branch 3.2 is using another fingerprint for Verification:

    Run the following command to get the last 16 hex digits of the fingerprint (before that you have to add keys to keychain)

    gpg --with-colons --list-key:
    pub:-:2048:1:082AB56BA14FE591:2016-07-15:::-:Zabbix LLC <[email protected]>::scESC:
    sub:-:2048:1F517F33E709712C:2016-07-15::::::e:
    pub:-:1024:1713D58E479EA5ED4:2012-10-28:::-:Zabbix SIA <[email protected]>::scESC:
    sub:-:1024:16:8BA826517E1DEF85:2012-10-28::::::e:

    So, DF517F33E709712C is used for branches until 3.0 and 082AB56BA14FE591 is for higher versions.
    Reprepro config part:

    distributions file

    Origin: zabbix
    Codename: 3.2
    Description: zabbix 3.2 mirror
    Architectures: amd64
    Components: main contrib non-free
    Update: - zabbix-3.2
    Contents: .gz
    Log: /var/log/reprepro/zabbix/3.2.log
    SignWith:your key

    update file

    Name: zabbix-3.2
    Method: http://repo.zabbix.com/zabbix/3.2/debian/
    Architectures: amd64
    Suite: wheezy
    VerifyRelease: 082AB56BA14FE591

    Comment

    Working...