linux:debian:apt-keyrings
Differences
This shows you the differences between two versions of the page.
| Next revision | Previous revision | ||
| linux:debian:apt-keyrings [2026/09/04 19:22] – created oscar | linux:debian:apt-keyrings [2026/09/06 05:23] (current) – [APT - Keyrings] oscar | ||
|---|---|---|---|
| Line 5: | Line 5: | ||
| |File/ | |File/ | ||
| |--|--|--| | |--|--|--| | ||
| - | |/ | + | |/ |
| + | |/ | ||
| |/ | |/ | ||
| |/ | |/ | ||
| - | |/ | ||
| |/ | |/ | ||
| |/ | |/ | ||
| Line 22: | Line 22: | ||
| * Understanding directory purposes is critical: / | * Understanding directory purposes is critical: / | ||
| * While keys can be retrieved from keyservers using gpg --recv-keys, | * While keys can be retrieved from keyservers using gpg --recv-keys, | ||
| + | |||
| + | ## Step 1 — Identifying the Components and Key Format | ||
| + | GPG, or GNU Privacy Guard, is an open-source encryption program used for signing, encrypting, and decrypting files and directories.GPG files are usually keyrings, which are files that hold multiple keys. | ||
| + | gpg is GPG’s command-line tool that can be used to authorize external repositories for use with apt. However, apt expects keys to be in a GPG keyring format (binary .gpg files). In order to use this command-line tool with ASCII-armored PGP files, you must convert them into this format. | ||
| + | PGP, or Pretty Good Privacy, is an proprietary alternative application. | ||
| + | |||
| + | Projects that require adding repositories with key verification will always provide you with a public key and a repository URI representing its exact location. For our Elasticsearch example, the documentation gives these components on their installation page. | ||
| + | |||
| + | Here are the components given for Elasticsearch: | ||
| + | |||
| + | Key: https:// | ||
| + | Repository: https:// | ||
| + | |||
| + | ## Step 2 — Downloading the Key and Converting to an apt Compatible File Type | ||
| + | On modern Debian systems, the / | ||
| + | ``` | ||
| + | # mkdir -p / | ||
| + | ``` | ||
| + | Then download, check and convert the key: | ||
| + | ``` | ||
| + | # curl -fsSL https:// | ||
| + | ``` | ||
| + | Next, you have to determine whether you are given a PGP or GPG file to work with: | ||
| + | ``` | ||
| + | # file tmp.key | ||
| + | -------------- | ||
| + | tmp.key: PGP public key block Public-Key (old) | ||
| + | |||
| + | # file tmp.key | ||
| + | -------------- | ||
| + | tmp.key: OpenPGP Public Key Version 4, Created Mon Sep 16 15:07:54 2013, RSA (Encrypt or Sign, 2048 bits); User ID; Signature; OpenPGP Certificate | ||
| + | ``` | ||
| + | The first result indicates that this is actually a PGP key file. Since apt expects keys to be stored in a GPG keyring format, convert the to gpg format with following: | ||
| + | |||
| + | ``` | ||
| + | # gpg --dearmor -o / | ||
| + | ``` | ||
| + | ## Step 3 — Adding the Repository to Your List of Package Sources | ||
| + | |||
| + | Next step is adding the repository to the apt package sources while explicitly linking it to the key you obtained. There are three methods to achieve this. Apt pulls sources from a central sources.list file, .list files in the sources.list.d directory, and .sources files in the sources.list.d directory. Though there is no functional difference between these options, using separate files in sources.list.d is generally easier to manage and maintain. | ||
| + | |||
| + | ### Option 1 — Adding to sources.list Directly | ||
| + | This involves inserting a line describing the source directly into / | ||
| + | ``` | ||
| + | # nano / | ||
| + | ------------------------------- | ||
| + | deb [arch=amd64, | ||
| + | ``` | ||
| + | This line contains the following information about the source: | ||
| + | |||
| + | * deb: Specifies that the source uses a Debian package format (Regular Binary) or deb-src (Source), depending on if you want a package or the source of the package. | ||
| + | * arch=amd64, | ||
| + | * signed-by=/ | ||
| + | * https:// | ||
| + | |||
| + | **Note:** `signed-by` is **optional**, | ||
| + | |||
| + | ### Option 2 — Creating a New .list File in sources.list.d | ||
| + | Create a new file in the sources.list.d directory. Apt parses both this directory and sources.list for repository additions. Create a new file and insert the appropriate line. The file is named elastic-9.x.list in the following example, but any unique filename will work: | ||
| + | ``` | ||
| + | # echo "deb [arch=amd64, | ||
| + | ``` | ||
| + | ### Option 3 — Creating a .sources File in sources.list.d | ||
| + | The third method writes to a .sources file instead of a .list file. This method uses the **deb822 multiline format**, which is more structured and less ambiguous than the single-line deb format, while remaining functionally equivalent.Create a new file: | ||
| + | ``` | ||
| + | # nano / | ||
| + | -------------------------------------------------- | ||
| + | Add the external repository using the deb822 format: | ||
| + | |||
| + | Types: deb | ||
| + | Architectures: | ||
| + | Signed-By: / | ||
| + | URIs: https:// | ||
| + | Suites: stable | ||
| + | Components: main | ||
| + | ``` | ||
| + | This format organizes the same information as the one-line format, but in a clearer, field-based structure. One difference is that it uses spaces instead of commas when specifying multiple values (for example, amd64 arm64 instead of amd64, | ||
| + | |||
| + | |||
linux/debian/apt-keyrings.1788549765.txt.gz · Last modified: by oscar
