You are not logged in.

#1 2020-11-21 16:48:53

twoion
ほやほや
Registered: 2015-08-10
Posts: 3,069

PSA: bunsen-keyring package refreshes

An update to the bunsen-keyring package has been released for the current BunsenLabs Lithium release, as well as all older releases, Helium and Hydrogen. The update contains a routine extension of the key expiration date until the year 2030. In order to ensure that your install can verify the signature on our package repositories after 2021-01-18, which is the current key expiration date, please make sure that you update your BunsenLabs system until then:

sudo apt-get update
sudo apt-get install bunsen-keyring
sudo apt-get update

The final apt-get update call should go through without any validation errors against the BunsenLabs repositories.

If you miss the update window till January 18, 2021, you can no longer receive the update using APT without intervention as APT will fail to verify our repository signatures using the expired key. In order to get the new key after the expiration date, download the following packages and install them manually:

Install the packages using the terminal by executing

sudo dpkg -i /path/to/the/package.deb

or by double-clicking on them using gdebi.


Per aspera ad astra.

Offline

#2 2020-11-21 22:45:32

hhh
Meep!
Registered: 2015-09-17
Posts: 11,001
Website

Re: PSA: bunsen-keyring package refreshes

Thanks for the update! I assume, if you miss the window, that you only need to install the one package relative to your BL OS version (just the lithium package if you run Lithium, for example.)

Offline

#3 2020-11-22 01:14:10

rbh
Member
From: Sweden/Vasterbotten/Rusfors
Registered: 2016-08-11
Posts: 912

Re: PSA: bunsen-keyring package refreshes

The new keyring should be installed whith normal update.

In terminal:

apt update
apt upgrade

Or in synaptic, Press button "Mark all upgrades" and "Execute"


// Regards rbh

Offline

#4 2020-11-23 11:17:07

grubernd
Member
From: Graz, AT
Registered: 2020-01-04
Posts: 23

Re: PSA: bunsen-keyring package refreshes

rbh wrote:

The new keyring should be installed whith normal update.

I was wondering the same .. shouldn't that package be a part of the system install?

I did as instructed and from the apt logs it looks like it actually had to install the package.

Edit: Will test on other machines later.

Last edited by grubernd (2020-11-23 11:18:54)

Offline

#5 2020-11-23 11:59:31

dbvolvox
Member
From: England
Registered: 2015-09-29
Posts: 89
Website

Re: PSA: bunsen-keyring package refreshes

rbh wrote:

The new keyring should be installed with normal update.

Confirming it was included in my normal update done today.

Offline

#6 2020-11-23 14:00:40

DeepDayze
Like sands through an hourglass...
From: In Linux Land
Registered: 2017-05-28
Posts: 1,074

Re: PSA: bunsen-keyring package refreshes

grubernd wrote:
rbh wrote:

The new keyring should be installed whith normal update.

I was wondering the same .. shouldn't that package be a part of the system install?

I did as instructed and from the apt logs it looks like it actually had to install the package.

Edit: Will test on other machines later.

The bunsen-keyring package is in the ISO, but if you do an install with a Bunsen ISO after January 18th (when the current certificate expires), you will then need to grab the updated keyring package and install manually as noted above as when you try to update a new install after the 18th of January it will fail unless you update the keyring.

Think this has bitten some people in the past.


Real Men Use Linux

Offline

#7 2020-11-23 14:49:26

twoion
ほやほや
Registered: 2015-08-10
Posts: 3,069

Re: PSA: bunsen-keyring package refreshes

DeepDayze wrote:
grubernd wrote:
rbh wrote:

The new keyring should be installed whith normal update.

I was wondering the same .. shouldn't that package be a part of the system install?

I did as instructed and from the apt logs it looks like it actually had to install the package.

Edit: Will test on other machines later.

The bunsen-keyring package is in the ISO, but if you do an install with a Bunsen ISO after January 18th (when the current certificate expires), you will then need to grab the updated keyring package and install manually as noted above as when you try to update a new install after the 18th of January it will fail unless you update the keyring.

Think this has bitten some people in the past.

The ISO images are about to be refreshed with updated packages. This problem will not occur if the user downloads the latest ISO images for the install.


Per aspera ad astra.

Offline

#8 2020-11-23 15:39:15

DeepDayze
Like sands through an hourglass...
From: In Linux Land
Registered: 2017-05-28
Posts: 1,074

Re: PSA: bunsen-keyring package refreshes

twoion wrote:
DeepDayze wrote:
grubernd wrote:

I was wondering the same .. shouldn't that package be a part of the system install?

I did as instructed and from the apt logs it looks like it actually had to install the package.

Edit: Will test on other machines later.

The bunsen-keyring package is in the ISO, but if you do an install with a Bunsen ISO after January 18th (when the current certificate expires), you will then need to grab the updated keyring package and install manually as noted above as when you try to update a new install after the 18th of January it will fail unless you update the keyring.

Think this has bitten some people in the past.

The ISO images are about to be refreshed with updated packages. This problem will not occur if the user downloads the latest ISO images for the install.

That's great to know. Thanks for that.


Real Men Use Linux

Offline

#9 2021-01-19 21:11:49

grubernd
Member
From: Graz, AT
Registered: 2020-01-04
Posts: 23

Re: PSA: bunsen-keyring package refreshes

I just used an install image from last year and had to update the key package by hand - as expected.

Have the official install images (download/torrent) been updated with the new key?

Offline

#10 2021-01-19 21:42:31

rbh
Member
From: Sweden/Vasterbotten/Rusfors
Registered: 2016-08-11
Posts: 912

Re: PSA: bunsen-keyring package refreshes

grubernd wrote:

I just used an install image from last year and had to update the key package by hand - as expected.

Have the official install images (download/torrent) been updated with the new key?

The last keyring bunsen-keyring_2020.10.10+bl9-1_all.deb , is from nov 2020.
The only Litium iso is from July 2020...

Instead of installing the keyring, I prefer importing the apt key and then update/upgrade all.

As root:

# wget https://ddl.bunsenlabs.org/ddl/BunsenLabs-RELEASE.asc -O- | apt-key add -

// Regards rbh

Offline

#11 2021-01-19 22:00:31

grubernd
Member
From: Graz, AT
Registered: 2020-01-04
Posts: 23

Re: PSA: bunsen-keyring package refreshes

rbh wrote:

The only Litium iso is from July 2020...

Instead of installing the keyring, I prefer importing the apt key and then update/upgrade all.

The missing key makes bl-welcome fail.

But since the script can not update itself, it can not fix the missing key or inform the user how to fix that himself. I know, BL is not meant for helpless people, but still.

Offline

#12 2021-01-20 01:22:19

johnraff
nullglob
From: Nagoya, Japan
Registered: 2015-09-09
Posts: 7,555
Website

Re: PSA: bunsen-keyring package refreshes

^See the top post for instructions.
https://forums.bunsenlabs.org/viewtopic … 30#p108430

twoion wrote:

If you miss the update window till January 18, 2021, you can no longer receive the update using APT without intervention as APT will fail to verify our repository signatures using the expired key. In order to get the new key after the expiration date...


...elevator in the Brain Hotel, broken down but just as well...
( a boring Japan blog (currently paused), idle Twitterings and GitStuff )

Introduction to the Bunsenlabs Lithium Desktop

Offline

#13 2021-01-20 06:26:01

ovum
Member
Registered: 2020-04-17
Posts: 60

Re: PSA: bunsen-keyring package refreshes

when i try to run the commands in the first post, i get the following errors:

sudo apt-get update
Hit:2 https://deb.debian.org/debian buster InRelease                           
Hit:3 https://deb.debian.org/debian-security buster/updates InRelease         
Get:1 http://eu.pkg.bunsenlabs.org/debian lithium InRelease [6,362 B]         
Hit:4 https://deb.debian.org/debian buster-updates InRelease                   
Err:1 http://eu.pkg.bunsenlabs.org/debian lithium InRelease
  The following signatures were invalid: EXPKEYSIG A0673F72FE62D9C5 Jens John (BunsenLabs Repository Signing Key) <dev@2ion.de>
Get:5 https://mega.nz/linux/MEGAsync/Debian_10.0 ./ InRelease [2,461 B]
Fetched 8,823 B in 4s (2,149 B/s)   
Reading package lists... Done
W: An error occurred during the signature verification. The repository is not updated and the previous index files will be used. GPG error: http://eu.pkg.bunsenlabs.org/debian lithium InRelease: The following signatures were invalid: EXPKEYSIG A0673F72FE62D9C5 Jens John (BunsenLabs Repository Signing Key) <dev@2ion.de>
W: Failed to fetch http://pkg.bunsenlabs.org/debian/dists/ … /InRelease  The following signatures were invalid: EXPKEYSIG A0673F72FE62D9C5 Jens John (BunsenLabs Repository Signing Key) <dev@2ion.de>
W: Some index files failed to download. They have been ignored, or old ones used instead.

please advise

Offline

#14 2021-01-20 06:43:08

johnraff
nullglob
From: Nagoya, Japan
Registered: 2015-09-09
Posts: 7,555
Website

Re: PSA: bunsen-keyring package refreshes

Did you follow this?

twoion wrote:

If you miss the update window till January 18, 2021, you can no longer receive the update using APT without intervention as APT will fail to verify our repository signatures using the expired key. In order to get the new key after the expiration date, download the following packages and install them manually:

Install the packages using the terminal by executing

sudo dpkg -i /path/to/the/package.deb

or by double-clicking on them using gdebi.


...elevator in the Brain Hotel, broken down but just as well...
( a boring Japan blog (currently paused), idle Twitterings and GitStuff )

Introduction to the Bunsenlabs Lithium Desktop

Offline

#15 2021-01-20 06:52:50

ovum
Member
Registered: 2020-04-17
Posts: 60

Re: PSA: bunsen-keyring package refreshes

d'oh!  Looks that was helpful in getting these commands to go through.  You are such a wonderful person to help me!

Offline

#16 2021-01-21 04:38:16

DeepDayze
Like sands through an hourglass...
From: In Linux Land
Registered: 2017-05-28
Posts: 1,074

Re: PSA: bunsen-keyring package refreshes

Another idea is to grab  the key packages to keep handy if installing from old ISOs and unable to grab the new ones.


Real Men Use Linux

Offline

Board footer

Powered by FluxBB