Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 205405 - Missing PGP keys used to sign Manifests
Summary: Missing PGP keys used to sign Manifests
Status: RESOLVED OBSOLETE
Alias: None
Product: Gentoo Infrastructure
Classification: Unclassified
Component: Developer account issues (show other bugs)
Hardware: All All
: High normal (vote)
Assignee: Gentoo Community Relations Team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2008-01-12 08:08 UTC by Christian Apeltauer
Modified: 2018-01-28 19:11 UTC (History)
6 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Christian Apeltauer 2008-01-12 08:08:56 UTC
I couldn't find DSA key ID C12B84C2 on a keyserver. This key is used to sign at least the manifests of dev-libs/libcdio, sys-apps/man, dev-lang/tk, dev-lang/ruby, sys-apps/file, dev-python/pygobject, media-libs/libsdl, sys-libs/com_err, sys-libs/ss, sys-fs/e2fsprogs, sys-libs/readline, sys-apps/man-pages, sys-devel/gettext (Portage snapshot of January 8th).
I have tried the keyservers pgp.mit.edu, subkeys.pgp.net and pgp.zdv.uni-mainz.de

Reproducible: Always

Steps to Reproduce:
1.
2.
3.
Comment 1 Jorge Manuel B. S. Vicetto (RETIRED) Gentoo Infrastructure gentoo-dev 2009-07-12 03:45:13 UTC
Opening up the bug.
Comment 2 Jorge Manuel B. S. Vicetto (RETIRED) Gentoo Infrastructure gentoo-dev 2009-07-12 06:02:50 UTC
@infra:

Is this (still) significant?
Comment 3 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2009-09-02 07:16:58 UTC
The commit to pygobject with that key belonged to eva.

I've CC'd him now so he can upload his key to the keyservers ASAP.
Comment 4 Gilles Dartiguelongue (RETIRED) gentoo-dev 2009-09-02 08:55:59 UTC
All my keys were on subkeys and other pgp directories way before I was accepted as a gentoo developer. I cannot remember a key with this id and I never touched at least half of these packages.
Comment 5 Torsten Veller (RETIRED) gentoo-dev 2009-09-02 12:15:00 UTC
My old Manifest checking script found the following keys missing on the keyservers:

B7750E047C7EDA6F keytoaster
B11ECF4214576049 gurligebis
8FD86F8AC12B84C2 vapier
9FFE5B633AAC4A61 vapier
EBBC2279261C6B17 vapier
Comment 6 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2009-09-02 20:47:37 UTC
eva:
hmm, I apologize. I just looked at the snapshot contents for january 8th, saw who's commit was active in the pygobject was in the Manifest, but didn't actually extract the key from the Manifest again. It was your key, so the original report was wrong.
http://sources.gentoo.org/viewcvs.py/gentoo-x86/dev-python/pygobject/Manifest?annotate=1.62

Feel free to un-CC yourself.
Comment 7 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2009-09-02 20:51:16 UTC
vapier, keytoaster, gurligebis:
Your GPG keys listed below are missing from the keyservers and are also not in the LDAP records. Please upload them and update LDAP.

B7750E047C7EDA6F keytoaster
B11ECF4214576049 gurligebis
8FD86F8AC12B84C2 vapier
9FFE5B633AAC4A61 vapier
EBBC2279261C6B17 vapier
(thanks to tove's script, repasted here so you get this in the email).
Comment 8 SpanKY gentoo-dev 2009-09-02 22:19:07 UTC
the mit server went down so i didnt bother pushing since, but ive used the pgp one now
Comment 9 Robin Johnson archtester Gentoo Infrastructure gentoo-dev Security 2009-09-03 01:13:20 UTC
vapier:
the pgp.mit.edu server works fine, I know they were doing some upgrades before. But I still don't find your key on any of the 6 boxes in the subkeys.pgp.net rotation.
Comment 10 SpanKY gentoo-dev 2009-09-05 10:17:52 UTC
i posted my latest keys only since there wasnt much point in posting expired ones.  pushed all of them now at any rate.
Comment 11 Bjarke Istrup Pedersen (RETIRED) gentoo-dev 2009-09-13 10:09:50 UTC
I have submitted 14576049 to pgp.mit.edu .
Comment 12 Torsten Veller (RETIRED) gentoo-dev 2009-09-16 06:32:43 UTC
0585EF5E2E18073A - spatz
B7750E047C7EDA6F - keytoaster
Comment 13 Tobias Heinlein (RETIRED) gentoo-dev 2009-09-16 18:57:08 UTC
I only just noticed this bug and uploaded my key now.
Comment 14 Dror Levin (RETIRED) gentoo-dev 2009-09-16 21:32:07 UTC
Uploaded my key to pgp.mit.edu just now. Sorry for the mess.
Comment 15 Torsten Veller (RETIRED) gentoo-dev 2009-09-25 04:33:50 UTC
No key is missing right now.
Comment 16 Torsten Veller (RETIRED) gentoo-dev 2009-12-21 08:57:54 UTC
vapier's new key (9B40969E) is missing.
Comment 17 Torsten Veller (RETIRED) gentoo-dev 2009-12-22 06:28:44 UTC
(In reply to comment #16)
> vapier's new key (9B40969E) is missing.

Now it's available.

Comment 18 Jeremy Olexa (darkside) (RETIRED) archtester gentoo-dev Security 2010-08-03 23:02:46 UTC
removing infra, nothing to do.
Comment 19 Torsten Veller (RETIRED) gentoo-dev 2010-08-31 05:55:29 UTC
      1 6F025FFE phosphan - dev-util/cdecl
      2 C3B1D339 idl0r - net-dns/bind net-misc/cfengine
Comment 20 Christian Ruppert (idl0r) gentoo-dev 2010-08-31 15:04:20 UTC
Fixed, thanks :)
Comment 21 Patrick Kursawe (RETIRED) gentoo-dev 2010-09-01 07:17:40 UTC
Hm... I am sure I uploaded the key. Will try again this evening, thanks for the hint.
Comment 22 Patrick Kursawe (RETIRED) gentoo-dev 2010-09-01 19:05:33 UTC
I think I got it right this time.
Comment 23 Christian Apeltauer 2011-03-11 18:47:57 UTC
Key
C1E2EC96
used e. g. for sys-libs/ncurses is missing for weeks now.
Comment 24 Torsten Veller (RETIRED) gentoo-dev 2011-03-11 19:06:44 UTC
Missing on keyservers:

9D9B20A3F87C90D6 tomka
682FCEA1C1E2EC96 vapier


Keys used after expiration
(new expiration sig should be send to keyservers):

23596A1064D4CF24 swegener
996AB56D84F20B43 angelos
D67FC261B5E39ED2 kolmodin
Comment 25 Torsten Veller (RETIRED) gentoo-dev 2011-03-25 06:21:51 UTC
(In reply to comment #24)
> Missing on keyservers:
> 
> 9D9B20A3F87C90D6 tomka
> 682FCEA1C1E2EC96 vapier
> 
> 
> Keys used after expiration
> (new expiration sig should be send to keyservers):
> 
> 23596A1064D4CF24 swegener
> D67FC261B5E39ED2 kolmodin
Comment 26 Lennart Kolmodin (RETIRED) gentoo-dev 2011-03-26 07:41:58 UTC
(In reply to comment #25)
> (In reply to comment #24)
> > Missing on keyservers:
> > 
> > 9D9B20A3F87C90D6 tomka
> > 682FCEA1C1E2EC96 vapier
> > 
> > 
> > Keys used after expiration
> > (new expiration sig should be send to keyservers):
> > 
> > 23596A1064D4CF24 swegener


Sent D67FC261B5E39ED2 to hkp://pgp.mit.edu
Comment 27 Sven Wegener gentoo-dev 2011-03-26 14:44:35 UTC
(In reply to comment #24)
> Keys used after expiration
> (new expiration sig should be send to keyservers):
> 
> 23596A1064D4CF24 swegener

Updated signature sent.
Comment 28 Thomas Kahle (RETIRED) gentoo-dev 2011-03-28 15:17:35 UTC
Ok, uploaded to pgp.mit.edu this time.  I used subkeys.pgp.net all the time before.  Seems to be non-working though.
Comment 29 Torsten Veller (RETIRED) gentoo-dev 2011-03-30 07:17:25 UTC
Missing on keyservers:

5E447D62A39C2CF1 ssuominen
Comment 30 Samuli Suominen (RETIRED) gentoo-dev 2011-03-30 08:29:52 UTC
(In reply to comment #29)
> Missing on keyservers:
> 
> 5E447D62A39C2CF1 ssuominen

It's at least in pgp.mit.edu now.
Comment 31 Torsten Veller (RETIRED) gentoo-dev 2011-03-31 06:37:42 UTC
Missing on keyservers:

2A24124BB658FA13 ultrabug
Comment 32 Ultrabug gentoo-dev 2011-03-31 07:29:30 UTC
(In reply to comment #31)
> Missing on keyservers:
> 
> 2A24124BB658FA13 ultrabug

Same as Tomka, I was using subkeys.pgp.net so far but it doesn't seem to work.
Uploaded to pgp.mit.edu, works good now. [1]

Cheers

[1] http://pgp.mit.edu:11371/pks/lookup?search=ultrabug&op=index
Comment 33 Torsten Veller (RETIRED) gentoo-dev 2011-04-23 06:34:33 UTC
Missing on keyservers:

F89ACD15712D74C5 polynomial-c
Comment 34 Lars Wendler (Polynomial-C) (RETIRED) gentoo-dev 2011-04-23 09:17:05 UTC
(In reply to comment #33)
> Missing on keyservers:
> 
> F89ACD15712D74C5 polynomial-c

Sent to pgp.mit.edu
Comment 35 Torsten Veller (RETIRED) gentoo-dev 2011-05-15 06:50:45 UTC
Missing on keyservers:

4EF42576F81EF355 arfrever
Comment 36 Torsten Veller (RETIRED) gentoo-dev 2012-05-23 03:48:39 UTC
Missing on keyservers:

1CD13C8AD4301342 flameeyes
6E4A8E0D0720FC74 miknix
B9CCB0BFBC35D737 psomas
Comment 37 Diego Elio Pettenò (RETIRED) gentoo-dev 2012-05-23 03:52:39 UTC
Gha, thanks! I had to replace the key because I lost access to the previous one (dead box at home), and forgot to send it up :( Now it's up.
Comment 38 Torsten Veller (RETIRED) gentoo-dev 2012-05-23 03:58:09 UTC
A0111542618E971F gienah

please update your key on the keyservers. your signature which extends expiration time is missing.
Comment 39 Angelo Arrifano (RETIRED) gentoo-dev 2012-05-25 23:20:28 UTC
(In reply to comment #36)
> Missing on keyservers:
> 
> 1CD13C8AD4301342 flameeyes
> 6E4A8E0D0720FC74 miknix
> B9CCB0BFBC35D737 psomas

sent to pgp.mit.edu
Comment 40 Mark Wright gentoo-dev 2012-06-03 05:58:20 UTC
(In reply to comment #38)
> A0111542618E971F gienah
> 
> please update your key on the keyservers. your signature which extends
> expiration time is missing.

sent to pgp.mit.edu
Comment 41 Alec Warner (RETIRED) archtester gentoo-dev Security 2013-01-05 21:05:16 UTC
Hey Tove, can we just run the script from cron to search for keys and auto-file bugs (or email devs) whose keys are missing?

-A
Comment 42 Stratos Psomadakis (RETIRED) gentoo-dev 2013-01-14 10:12:51 UTC
(In reply to comment #36)
> Missing on keyservers:
> 
> 1CD13C8AD4301342 flameeyes
> 6E4A8E0D0720FC74 miknix
> B9CCB0BFBC35D737 psomas

sent to pgp.mit.edu
Comment 43 Pacho Ramos gentoo-dev 2014-11-15 18:32:06 UTC
What is pending here? And, what are we (comrel) expected to do? :)

Thanks
Comment 44 Andreas K. Hüttel archtester gentoo-dev 2018-01-28 19:11:28 UTC
(In reply to Pacho Ramos from comment #43)
> What is pending here? And, what are we (comrel) expected to do? :)
> 
> Thanks

Keys that are not on the keyservers can't push to git, so this can be closed as obsolete.