User Tools

Site Tools


linux:debian:apt-keyrings

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
linux:debian:apt-keyrings [2026/09/04 20:11] – [Step 2 — Downloading the Key and Converting to an apt Compatible File Type] oscarlinux:debian:apt-keyrings [2026/09/06 05:23] (current) – [APT - Keyrings] oscar
Line 5: Line 5:
 |File/Directory Path|Status|Description| |File/Directory Path|Status|Description|
 |--|--|--| |--|--|--|
-|/etc/apt/keyrings/|Recommended |Standard directory for storing third-party repository GPG keys. Kept isolated per repository and explicitly referenced via the signed-by option in APT sources configuration files.|+|/etc/apt/keyrings/|Recommended |Standard directory for storing **third-party repository GPG keys**. Kept isolated per repository and explicitly referenced via the signed-by option in APT sources configuration files.| 
 +|/usr/share/keyrings/|Standard|Directory managed by OS package manager (dpkg/apt) containing **official system distribution signing keys** (e.g., ubuntu-archive-keyring.gpg or debian-archive-keyring.gpg).|
 |/etc/apt/trusted.gpg.d/|Legacy / Active|Directory containing fragment keyrings (or export files with extension .gpg or .asc). APT trusts all keys in this directory globally for any repository unless restricted.| |/etc/apt/trusted.gpg.d/|Legacy / Active|Directory containing fragment keyrings (or export files with extension .gpg or .asc). APT trusts all keys in this directory globally for any repository unless restricted.|
 |/etc/apt/trusted.gpg|Deprecated|Legacy primary keyring file where apt-key add previously stored GPG keys. Deprecated because any key added here is trusted globally across every repository.| |/etc/apt/trusted.gpg|Deprecated|Legacy primary keyring file where apt-key add previously stored GPG keys. Deprecated because any key added here is trusted globally across every repository.|
-|/usr/share/keyrings/|Standard|Directory managed by OS package manager (dpkg/apt) containing official system distribution signing keys (e.g., ubuntu-archive-keyring.gpg or debian-archive-keyring.gpg).| 
 |/etc/apt/sources.list|Active|Main system configuration file for APT software repositories. Accepts signed-by=/path/to/key.gpg directives inline to pin a key to a specific repository line.| |/etc/apt/sources.list|Active|Main system configuration file for APT software repositories. Accepts signed-by=/path/to/key.gpg directives inline to pin a key to a specific repository line.|
 |/etc/apt/sources.list.d/|Active|Directory containing modular repository source configuration files (.list or .sources). Frequently pairs with custom keyrings stored under /etc/apt/keyrings/.| |/etc/apt/sources.list.d/|Active|Directory containing modular repository source configuration files (.list or .sources). Frequently pairs with custom keyrings stored under /etc/apt/keyrings/.|
Line 72: Line 72:
 This line contains the following information about the source: This line contains the following information about the source:
  
-  * deb: Specifies that the source uses a Debian package format+  * deb: Specifies that the source uses a Debian package format (Regular Binary) or deb-src (Source), depending on if you want a package or the source of the package. 
   * arch=amd64,arm64: Specifies the architectures the APT data will be downloaded for   * arch=amd64,arm64: Specifies the architectures the APT data will be downloaded for
   * signed-by=/etc/apt/keyrings/elastic-9.x.gpg: Specifies the key used to authorize this source. This is a required addition in modern APT usage and ensures that the key is only trusted for this repository   * signed-by=/etc/apt/keyrings/elastic-9.x.gpg: Specifies the key used to authorize this source. This is a required addition in modern APT usage and ensures that the key is only trusted for this repository
   * https://artifacts.elastic.co/packages/9.x/apt stable main: The URI representing the repository location   * https://artifacts.elastic.co/packages/9.x/apt stable main: The URI representing the repository location
 +
 +**Note:** `signed-by` is **optional**, not mandatory. When a deb line has no signed-by option, APT falls back to checking the repo's release signature against all keys in its default trust stores: /etc/apt/trusted.gpg or in every file in /etc/apt/trusted.gpg.d/*.gpg.
  
 ### Option 2 — Creating a New .list File in sources.list.d ### Option 2 — Creating a New .list File in sources.list.d
linux/debian/apt-keyrings.1788552684.txt.gz · Last modified: by oscar