Re: How can I disable signature check for a Debian CD?



On Fri, Sep 10, 2010 at 03:36:03PM +0300, Onur Aslan wrote:
On Fri, Sep 10, 2010 at 07:25:54AM -0500, Kumar Appaiah wrote:
Please paste the error message here. It would contain the key ID.

There is no error. Debian CD images doesn't have any signature or key.

I see. I thought apt-get update would actually warn about the missing
keys; maybe I was wrong.

You could try looking for the Release.gpg file in your CD and trying
out this:

gpg --verify Release.gpg Release

That would tell you the keys which were used to sign the files. For
instance:

gpg: Signature made Sat 04 Sep 2010 12:30:28 PM CDT using RSA key ID 55BE302B
gpg: Can't check signature: public key not found
gpg: Signature made Sat 04 Sep 2010 12:37:54 PM CDT using DSA key ID F42584E6
gpg: Can't check signature: public key not found

Please let me know if this helps.

Kumar


--
To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx
with a subject of "unsubscribe". Trouble? Contact listmaster@xxxxxxxxxxxxxxxx
Archive: http://lists.debian.org/20100910134932.GD27363@xxxxxxxxxxxxxxxxxxxxx



Relevant Pages

  • Re: OT: More about GPG signing
    ... gpg: Can't check signature: public key not found ... Am I expected to go to some keyserver to find the sender's public key? ... If you have installed Enigmail then go ahead & do it. ...
    (Debian-User)
  • Re: [SLE] pgp howto
    ... > Assuming you have already imported the public key: ... gpg: Can't check signature: public key not found ... Using the gpg --edit-key UID command for the key that needs to be signed you ...
    (SuSE)
  • Re: [OT] Manually verifying PGP/MIME signature with GPG
    ... No FUD in there, safe to proceed. ... gpg: ... gpg: WARNING: This key is not certified with a trusted signature! ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: backports
    ... gpg: checking the trustdb ... public key 3C093EEF is 29789 seconds newer than the signature ... If you really want to check that a certain key belongs to a Debian Developer, ...
    (Debian-User)
  • Re: Checking SHA256SUMS against SHA256SUMS.sign .
    ... gpg --verify SHA256SUMS.sign SHA256SUMS ... Now, under normal user: ... Good signature from "Debian Live Signing Key ... To trust a key, the following algorithm is used: ...
    (Debian-User)