WEBlog -- Wouter's Eclectic Blog

Thu, 19 Mar 2009

Dealing with apt's GPG signing stuff -- the right way.

Philippe blogs about how one can import a GPG key into apt's GPG keyring so that it will stop complaining about unknown keys. While his method will work, it has a major flaw:

Importing random keys without checking them first makes secure apt totally useless, since it allows an attacker to replace an apt repository with another one that he signed with his own key and you won't even notice because you blindly import keys anyway.

So what's the right way? Depends: