RikMills | LP: #2095004 after rsync update | 05:10 |
---|---|---|
-ubottu:#ubuntu-security- Launchpad bug 2095004 in rsync (Ubuntu) "Internal hashtable error: illegal key supplied!" [Undecided, Confirmed] https://launchpad.net/bugs/2095004 | 05:10 | |
JackFrost | Debian #1093160 | 05:20 |
-ubottu:#ubuntu-security- Debian bug 1093160 in rsync "rsync: failed verification -- update discarded" [Grave, Open] https://bugs.debian.org/1093160 | 05:20 | |
=== steve2 is now known as Steeve | ||
oerheks | hi, how do i file a bugreport against Jammy/E: The repository 'https://esm.ubuntu.com/apps/ubuntu jammy-apps-security Release' is no longer signed. | 22:15 |
oerheks | ubuntu-advantage-tools? | 22:16 |
sarnold | oerheks: the https://esm.ubuntu.com/apps/ubuntu/dists/jammy-apps-security/InRelease that I just downloaded now was signed by E8A443CE358113D187BEE0E6AB01A101DB53907B -- this key is in /usr/share/keyrings/ubuntu-pro-esm-apps.gpg which is provided by ubuntu-pro-client -- are these the same things you're seeing? | 23:00 |
oerheks | it is fixed not, sarnold | 23:00 |
sarnold | ah! yay | 23:00 |
oerheks | c/not/now | 23:00 |
oerheks | just a glitch? | 23:01 |
oerheks | for some minutes? | 23:01 |
sarnold | I wonder what would have caused that :/ | 23:01 |
sarnold | https should protect against the silliest causes of errors | 23:02 |
sarnold | oerheks: hmm.. maybe check dmesg, maybe there's segfaults in there or block storage errors? I'm not sure how exactly this would have worked well enough to get you the files, but then give you files that fail.. | 23:05 |
oerheks | how do i get my key print? | 23:06 |
sarnold | oerheks: something like this: | 23:12 |
sarnold | $ gpg --verify /var/lib/apt/lists/esm.ubuntu.com_apps_ubuntu_dists_focal-apps-security_InRelease | 23:13 |
sarnold | gpg: Signature made Thu Jan 16 04:13:10 2025 UTC | 23:13 |
sarnold | gpg: using RSA key E8A443CE358113D187BEE0E6AB01A101DB53907B | 23:13 |
sarnold | gpg: Can't check signature: No public key | 23:13 |
sarnold | but probably /var/lib/apt/lists/esm.ubuntu.com_apps_ubuntu_dists_jammy-apps-security_InRelease | 23:13 |
oerheks | gpg --verify /var/lib/apt/lists/esm.ubuntu.com_apps_ubuntu_dists_jammy-apps-security_InRelease | 23:14 |
oerheks | gpg: Signature made do 16 jan 2025 23:13:20 CET | 23:14 |
oerheks | gpg: using RSA key E8A443CE358113D187BEE0E6AB01A101DB53907B | 23:14 |
oerheks | gpg: Can't check signature: No public key | 23:14 |
oerheks | same | 23:14 |
oerheks | just to check, thanks | 23:14 |
sarnold | oh yeah, and to actually validate it, rather than just find out what key signed it :) | 23:16 |
sarnold | gpg --keyring /usr/share/keyrings/ubuntu-pro-esm-apps.gpg --verify /var/lib/apt/lists/esm.ubuntu.com_apps_ubuntu_dists_focal-apps-security_InRelease | 23:16 |
oerheks | jammy | 23:17 |
oerheks | gpg --keyring /usr/share/keyrings/ubuntu-pro-esm-apps.gpg --verify /var/lib/apt/lists/esm.ubuntu.com_apps_ubuntu_dists_jammy-apps-security_InRelease | 23:17 |
oerheks | gpg: Signature made do 16 jan 2025 23:13:20 CET | 23:17 |
oerheks | gpg: using RSA key E8A443CE358113D187BEE0E6AB01A101DB53907B | 23:17 |
oerheks | gpg: Good signature from "Ubuntu Apps Automatic Signing Key <esm@canonical.com>" [unknown] | 23:17 |
oerheks | gpg: WARNING: This key is not certified with a trusted signature! | 23:17 |
oerheks | gpg: There is no indication that the signature belongs to the owner. | 23:17 |
oerheks | Primary key fingerprint: E8A4 43CE 3581 13D1 87BE E0E6 AB01 A101 DB53 907B | 23:17 |
oerheks | some warnings, should i be concerned? | 23:18 |
sarnold | nah, that just means you haven't marked any of the keys that sign this one as "trusted" | 23:19 |
oerheks | oh | 23:19 |
sarnold | I might have published signatures on some of our keys just so I could silence these things for myself :) but it's really no big deal, so long as you know you received the key from a trusted source | 23:20 |
oerheks | it is an old discussion, how to trust the keys on your iso? | 23:21 |
oerheks | as basis | 23:21 |
sarnold | bingo | 23:21 |
oerheks | ubuntu core did something right | 23:21 |
oerheks | register.. | 23:21 |
oerheks | then https does not matter anymore | 23:22 |
JanC | I assume the keys are signed by various people | 23:43 |
JanC | at least the old release keys used to be? | 23:45 |
Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!