User Tools

Site Tools


linux:debian:apt-keyrings

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Next revision
Previous revision
linux:debian:apt-keyrings [2026/09/04 19:22] – created oscarlinux:debian:apt-keyrings [2026/09/06 05:23] (current) – [APT - Keyrings] oscar
Line 5: Line 5:
 |File/Directory Path|Status|Description| |File/Directory Path|Status|Description|
 |--|--|--| |--|--|--|
-|/etc/apt/keyrings/|Recommended |Standard directory for storing third-party repository GPG keys. Kept isolated per repository and explicitly referenced via the signed-by option in APT sources configuration files.|+|/etc/apt/keyrings/|Recommended |Standard directory for storing **third-party repository GPG keys**. Kept isolated per repository and explicitly referenced via the signed-by option in APT sources configuration files.| 
 +|/usr/share/keyrings/|Standard|Directory managed by OS package manager (dpkg/apt) containing **official system distribution signing keys** (e.g., ubuntu-archive-keyring.gpg or debian-archive-keyring.gpg).|
 |/etc/apt/trusted.gpg.d/|Legacy / Active|Directory containing fragment keyrings (or export files with extension .gpg or .asc). APT trusts all keys in this directory globally for any repository unless restricted.| |/etc/apt/trusted.gpg.d/|Legacy / Active|Directory containing fragment keyrings (or export files with extension .gpg or .asc). APT trusts all keys in this directory globally for any repository unless restricted.|
 |/etc/apt/trusted.gpg|Deprecated|Legacy primary keyring file where apt-key add previously stored GPG keys. Deprecated because any key added here is trusted globally across every repository.| |/etc/apt/trusted.gpg|Deprecated|Legacy primary keyring file where apt-key add previously stored GPG keys. Deprecated because any key added here is trusted globally across every repository.|
-|/usr/share/keyrings/|Standard|Directory managed by OS package manager (dpkg/apt) containing official system distribution signing keys (e.g., ubuntu-archive-keyring.gpg or debian-archive-keyring.gpg).| 
 |/etc/apt/sources.list|Active|Main system configuration file for APT software repositories. Accepts signed-by=/path/to/key.gpg directives inline to pin a key to a specific repository line.| |/etc/apt/sources.list|Active|Main system configuration file for APT software repositories. Accepts signed-by=/path/to/key.gpg directives inline to pin a key to a specific repository line.|
 |/etc/apt/sources.list.d/|Active|Directory containing modular repository source configuration files (.list or .sources). Frequently pairs with custom keyrings stored under /etc/apt/keyrings/.| |/etc/apt/sources.list.d/|Active|Directory containing modular repository source configuration files (.list or .sources). Frequently pairs with custom keyrings stored under /etc/apt/keyrings/.|
Line 22: Line 22:
   * Understanding directory purposes is critical: /etc/apt/keyrings stores administrator-managed keys, /usr/share/keyrings contains package-managed keys, and /etc/apt/trusted.gpg.d/ represents the deprecated legacy approach that should be avoided.   * Understanding directory purposes is critical: /etc/apt/keyrings stores administrator-managed keys, /usr/share/keyrings contains package-managed keys, and /etc/apt/trusted.gpg.d/ represents the deprecated legacy approach that should be avoided.
   * While keys can be retrieved from keyservers using gpg --recv-keys, downloading them directly via HTTPS is more reliable and avoids potential issues with slow, unreliable, or blocked keyservers, though both methods work with scoped keyrings.   * While keys can be retrieved from keyservers using gpg --recv-keys, downloading them directly via HTTPS is more reliable and avoids potential issues with slow, unreliable, or blocked keyservers, though both methods work with scoped keyrings.
 +
 +## Step 1 — Identifying the Components and Key Format
 +GPG, or GNU Privacy Guard, is an open-source encryption program used for signing, encrypting, and decrypting files and directories.GPG files are usually keyrings, which are files that hold multiple keys.
 +gpg is GPG’s command-line tool that can be used to authorize external repositories for use with apt. However, apt expects keys to be in a GPG keyring format (binary .gpg files). In order to use this command-line tool with ASCII-armored PGP files, you must convert them into this format.
 +PGP, or Pretty Good Privacy, is an proprietary alternative application. 
 +
 +Projects that require adding repositories with key verification will always provide you with a public key and a repository URI representing its exact location. For our Elasticsearch example, the documentation gives these components on their installation page.
 +
 +Here are the components given for Elasticsearch:
 +
 +    Key: https://artifacts.elastic.co/GPG-KEY-elasticsearch
 +    Repository: https://artifacts.elastic.co/packages/9.x/apt stable main
 +
 +## Step 2 — Downloading the Key and Converting to an apt Compatible File Type
 +On modern Debian systems, the /etc/apt/keyrings directory is the recommended location for storing administrator-managed keyrings. Create this directory if it does not already exist:
 +```
 +# mkdir -p /etc/apt/keyrings
 +```
 +Then download, check and convert the key:
 +```
 +# curl -fsSL https://artifacts.elastic.co/GPG-KEY-elasticsearch > tmp.key
 +```
 +Next, you have to determine whether you are given a PGP or GPG file to work with:
 +```
 +# file tmp.key
 +--------------
 +tmp.key: PGP public key block Public-Key (old)
 +
 +# file tmp.key
 +--------------
 +tmp.key: OpenPGP Public Key Version 4, Created Mon Sep 16 15:07:54 2013, RSA (Encrypt or Sign, 2048 bits); User ID; Signature; OpenPGP Certificate
 +```
 +The first result indicates that this is actually a PGP key file. Since apt expects keys to be stored in a GPG keyring format, convert the to gpg format with following:
 +
 +```
 +# gpg --dearmor -o /etc/apt/keyrings/elastic-9.x.gpg  tmp.key
 +```
 +## Step 3 — Adding the Repository to Your List of Package Sources
 +
 +Next step is adding the repository to the apt package sources while explicitly linking it to the key you obtained. There are three methods to achieve this. Apt pulls sources from a central sources.list file, .list files in the sources.list.d directory, and .sources files in the sources.list.d directory. Though there is no functional difference between these options, using separate files in sources.list.d is generally easier to manage and maintain.
 +
 +### Option 1 — Adding to sources.list Directly
 +This involves inserting a line describing the source directly into /etc/apt/sources.list, the primary file containing apt sources. There are multiple sources in this file, including the default sources that come with Debian. It is perfectly acceptable to edit this file directly, though Option 2 and Option 3 present more modular solutions that are easier to edit and maintain. Add the external repository to the bottom of the file:
 +```
 +# nano /etc/apt/sources.list
 +-------------------------------
 +deb [arch=amd64,arm64 signed-by=/etc/apt/keyrings/elastic-9.x.gpg] https://artifacts.elastic.co/packages/9.x/apt stable main
 +```
 +This line contains the following information about the source:
 +
 +  * deb: Specifies that the source uses a Debian package format (Regular Binary) or deb-src (Source), depending on if you want a package or the source of the package. 
 +  * arch=amd64,arm64: Specifies the architectures the APT data will be downloaded for
 +  * signed-by=/etc/apt/keyrings/elastic-9.x.gpg: Specifies the key used to authorize this source. This is a required addition in modern APT usage and ensures that the key is only trusted for this repository
 +  * https://artifacts.elastic.co/packages/9.x/apt stable main: The URI representing the repository location
 +
 +**Note:** `signed-by` is **optional**, not mandatory. When a deb line has no signed-by option, APT falls back to checking the repo's release signature against all keys in its default trust stores: /etc/apt/trusted.gpg or in every file in /etc/apt/trusted.gpg.d/*.gpg.
 +
 +### Option 2 — Creating a New .list File in sources.list.d
 +Create a new file in the sources.list.d directory. Apt parses both this directory and sources.list for repository additions. Create a new file and insert the appropriate line. The file is named elastic-9.x.list in the following example, but any unique filename will work:
 +```
 +# echo "deb [arch=amd64,arm64 signed-by=/etc/apt/keyrings/elastic-9.x.gpg] https://artifacts.elastic.co/packages/9.x/apt stable main" | sudo tee /etc/apt/sources.list.d/elastic-9.x.list > /dev/null
 +```
 +### Option 3 — Creating a .sources File in sources.list.d
 +The third method writes to a .sources file instead of a .list file. This method uses the **deb822 multiline format**, which is more structured and less ambiguous than the single-line deb format, while remaining functionally equivalent.Create a new file:
 +```
 +# nano /etc/apt/sources.list.d/elastic-9.x.sources
 +--------------------------------------------------
 +Add the external repository using the deb822 format:
 +
 +Types: deb
 +Architectures: amd64 arm64
 +Signed-By: /etc/apt/keyrings/elastic-9.x.gpg
 +URIs: https://artifacts.elastic.co/packages/9.x/apt
 +Suites: stable
 +Components: main
 +```
 +This format organizes the same information as the one-line format, but in a clearer, field-based structure. One difference is that it uses spaces instead of commas when specifying multiple values (for example, amd64 arm64 instead of amd64,arm64).
 +
 +
linux/debian/apt-keyrings.1788549765.txt.gz · Last modified: by oscar