1

Topic: Distro signing key expired warning during authenticity check

$ gpg --keyserver pgp.mit.edu --recv-key "C92B AA71 3B8D 53D3 CAE6 3FC9 E697 4752 F970 4456"
gpg: directory '/home/user/.gnupg' created
gpg: keybox '/home/user/.gnupg/pubring.kbx' created
gpg: /home/user/.gnupg/trustdb.gpg: trustdb created
gpg: key E6974752F9704456: public key "André Silva <emulatorman@hyperbola.info>" imported
gpg: Total number processed: 1
gpg:               imported: 1
$ gpg --verify hyperbola-milky-way-v0.4.2-dual.iso.sha512.sig
gpg: assuming signed data in 'hyperbola-milky-way-v0.4.2-dual.iso.sha512'
gpg: Signature made Wed Dec 21 14:48:22 2022 PST
gpg:                using RSA key C92BAA713B8D53D3CAE63FC9E6974752F9704456
gpg: Good signature from "André Silva <emulatorman@hyperbola.info>" [expired]
gpg:                 aka "André Silva <emulatorman@riseup.net>" [expired]
gpg:                 aka "[jpeg image of size 16875]" [expired]
gpg: Note: This key has expired!
Primary key fingerprint: C92B AA71 3B8D 53D3 CAE6  3FC9 E697 4752 F970 4456

2

Re: Distro signing key expired warning during authenticity check

Thanks for noting. Will be worked on.

Human being in favor with clear principles and so also for freedom in soft- and hardware!

Certainly anyone who has the power to make you believe absurdities has the power to make you commit injustices: For a life of every being full with peace and kindness, including diversity and freedom. Capitalism is destroying our minds, the planet itself and the universe in the end!

3

Re: Distro signing key expired warning during authenticity check

Should be resolved.

Human being in favor with clear principles and so also for freedom in soft- and hardware!

Certainly anyone who has the power to make you believe absurdities has the power to make you commit injustices: For a life of every being full with peace and kindness, including diversity and freedom. Capitalism is destroying our minds, the planet itself and the universe in the end!

4

Re: Distro signing key expired warning during authenticity check

throgh wrote:

Should be resolved.

I thought that we were supposed to disable key signing due to archlinux keyring issues...

wink

HyperbolaBSD: The Future of Secure Libre Lightweight Operating Systems!

5

Re: Distro signing key expired warning during authenticity check

Hyperbola has for package-signing only own ones, but for file-signing there are nevertheless keys from developers used and sure those can and will expire.

Human being in favor with clear principles and so also for freedom in soft- and hardware!

Certainly anyone who has the power to make you believe absurdities has the power to make you commit injustices: For a life of every being full with peace and kindness, including diversity and freedom. Capitalism is destroying our minds, the planet itself and the universe in the end!