Skip to content

Explain APT signing keys and add a deb822 example - #429

Open
pinguinfuss wants to merge 1 commit into
git-pkgs:mainfrom
pinguinfuss:issue-147-apt-docs
Open

pinguinfuss wants to merge 1 commit into
git-pkgs:mainfrom
pinguinfuss:issue-147-apt-docs

Conversation

@pinguinfuss

Copy link
Copy Markdown
Contributor

Closes #147. Point 1 is already covered by debian_repositories; this fills
the two docs gaps (points 2 and 3).

The proxy serves the upstream's InRelease and Release files unchanged, so
there is no proxy key: APT keeps verifying with the distribution's archive
keyring (debian-archive-keyring / ubuntu-keyring). The README now says
that, names the Ubuntu keyring file and mentions signed-by for both formats.

It also adds a deb822 .sources example next to the existing .list line,
and the "replace your existing entries" step now mentions debian.sources /
ubuntu.sources, since newer releases ship those instead of sources.list.

The setup snippet on the dashboard still shows the .list line only. I left
it alone to keep this to the README; happy to add the deb822 variant there in
a follow-up if you want it.

Signed indexes pass through unchanged, so apt keeps using the distro's
archive keyring. No proxy key needed.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Compatibility with Ubuntu

1 participant