Invalid GPG signature http://ddebs.ubuntu.com/dists/trusty/Release.gpg

Bug #1345877 reported by Anders Kaseorg
300
This bug affects 9 people
Affects Status Importance Assigned to Milestone
ubuntu-archive-publishing
Fix Released
Undecided
Unassigned

Bug Description

For the last week or so, with the trusty ddebs repository in sources.list (deb http://ddebs.ubuntu.com trusty main restricted universe multiverse), apt-get update fails with

W: An error occurred during the signature verification. The repository is not updated and the previous index files will be used. GPG error: http://ddebs.ubuntu.com trusty Release: The following signatures were invalid: BADSIG ECDCAD72428D7C01 Ubuntu Debug Symbol Archive Automatic Signing Key <email address hidden>

W: Failed to fetch http://ddebs.ubuntu.com/dists/trusty/Release

W: Some index files failed to download. They have been ignored, or old ones used instead.

You can check manually that the signature is bad:

$ wget -q http://ddebs.ubuntu.com/dists/trusty/Release.gpg http://ddebs.ubuntu.com/dists/trusty/Release
$ gpg --verify Release.gpg Release
gpg: Signature made Sun 20 Jul 2014 06:15:32 AM EDT using DSA key ID 428D7C01
gpg: BAD signature from "Ubuntu Debug Symbol Archive Automatic Signing Key <email address hidden>"

Revision history for this message
Anders Kaseorg (andersk) wrote :

Notably, the GPG timestamp on Release.gpg is consistent with its HTTP timestamp, but the HTTP timestamp on Release is a few hours ahead of that. So I guess Release is getting uploaded without a corresponding Release.gpg, hence the inconsistency.

Richard Hansen (rhansen)
Changed in ubuntu-archive-publishing:
status: New → Confirmed
information type: Public → Public Security
Revision history for this message
Martin Pitt (pitti) wrote :

I fixed the existing signatures, sorry about that.

Changed in ubuntu-archive-publishing:
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.