JP Vossen via plug on 16 Feb 2021 11:47:17 -0800


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

[PLUG] Michael Prokop: How to properly use 3rd party Debian repository signing keys with apt


Neat article:

https://michael-prokop.at/blog/2021/02/16/how-to-properly-use-3rd-party-debian-repository-signing-keys-with-apt/
Michael Prokop: How to properly use 3rd party Debian repository signing keys with apt
	(Blogging this, since this is a recurring anti-pattern I noticed at several customers and often comes up during deployments of 3rd party repositories.)

	Many upstream projects provide Debian repository instructions like this:
		curl -fsSL https://example.com/stable/debian.gpg | sudo apt-key add -
	Do not follow this, for different reasons, including:
----end quote----

...go read the article...

Later,
JP
--  -------------------------------------------------------------------
JP Vossen, CISSP | http://www.jpsdomain.org/ | http://bashcookbook.com/
___________________________________________________________________________
Philadelphia Linux Users Group         --        http://www.phillylinux.org
Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce
General Discussion  --   http://lists.phillylinux.org/mailman/listinfo/plug