Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 678614 - Installation media do not contain PGP keys to verify stage archives
Summary: Installation media do not contain PGP keys to verify stage archives
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Release Media
Classification: Unclassified
Component: InstallCD (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Release Team
URL:
Whiteboard:
Keywords: PullRequest
Depends on:
Blocks:
 
Reported: 2019-02-23 07:27 UTC by Sebastian Hamann
Modified: 2023-08-19 19:14 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sebastian Hamann 2019-02-23 07:27:55 UTC
The minimal installation CD for amd64 does not seem to contain the release engineering keys that are required to verify the stage archive.
The handbook instructs the user to run "gpg --verify" on the downloaded files, which returns "Can't check signature: No public key".

Of course, the handbook could be updated to include instructions on downloading the relevant keys, similar to the section about downloading the ISO.
But I believe they should be part of the installation media, because:
1. It would be easier for the user. Less steps mean probably fewer users skip them, resulting in more verified Gentoo installations.
2. Right now, the security-conscious user needs to get the keys from some keyserver and then compare the fingerprints to those published on the web site, checking that the HTTPS connection is good. With the keys on the installation media, no extra steps are needed to establish trust, since they are verified by checking the ISOs signature.
3. IMHO, the key needed to verify files downloaded during installation process simply belong on official installation media.

Note: install-amd64-minimal-20190212T214502Z.iso is the only ISO I tested. May apply to other ISOs as well.

Reproducible: Always

Steps to Reproduce:
1. Download minimal installation CD
2. Follow the instructions in the handbook on downloading and verifying a stage archive
Actual Results:  
Verification fails with:

gpg: Signature made Fri Feb 22 01:45:08 2019 UTC
gpg:                using RSA key 13EBBDBEDE7A12775DFDB1BABB572E0E2D182910
gpg: Can't check signature: No public key

Expected Results:  
The instructions in the handbook simply work :)
Comment 1 Joe Kappus 2023-08-04 10:48:15 UTC
Yeah, that's a bug, here's the handbook page in question: https://wiki.gentoo.org/wiki/Handbook:Parts/Installation/Media
Comment 2 Andreas K. Hüttel archtester gentoo-dev 2023-08-19 19:14:02 UTC
In @system now.