Jan-Piet Mens :: If only I'd known ... Debian repo signing

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Debian 13 introduced stricter security policies that reject SHA1-based GPG signatures, causing issues with package repository verification. The author discovered that repositories can use keyrings containing multiple GPG keys, enabling smooth key rollover without breaking client installations. This approach allows maintaining both old and new signing keys simultaneously during transitions, avoiding the Catch-22 situation where clients can't verify updates due to changed keys.

3m read timeFrom jpmens.net
Post cover image

Sort: