Apt key expired (with solution)

hi @mia , I am using an RPM-based distro, hence the rpm command :wink: so the apt-key command does not work here

Gosh!! I totally missed that-- sorry!!

Let me check with our engineers :slight_smile:

EDIT: Here you go!

sudo rpm -e gpg-pubkey-accaf35c-57d58c01
sudo rpm --import https://d2t3ff60b2tol4.cloudfront.net/repomd.xml.key

1 Like

thanks, it works now!

1 Like

Good information thanks for sharing
vmware

sudo apt-key adv --keyserver hkp://keyserver.ubuntu.com:80 --recv-keys ACCAF35C
I ran the command but keep getting the error. Here is the output. Running Linux Mint 20.1

gpg: no running Dirmngr - starting '/usr/bin/dirmngr'
gpg: waiting for the dirmngr to come up ... (5s)
gpg: connection to dirmngr established
gpg: data source: http://162.213.33.8:11371
gpg: key A684470CACCAF35C: number of dropped non-self-signatures: 1
gpg: pub  rsa2048/A684470CACCAF35C 2012-09-10  Insynchq Inc <services@insynchq.com>
gpg: Note: signature key 06BBDC2602DFE7E7 expired Thu 10 Sep 2020 12:12:28 PM CDT
gpg: key A684470CACCAF35C: "Insynchq Inc <services@insynchq.com>" not changed
gpg: Total number processed: 1
gpg:              unchanged: 1

Hi @affiliatex

Can you run the following and then send us the output?

sudo apt-key del ACCAF35C
cd /tmp
wget https://d2t3ff60b2tol4.cloudfront.net/repomd.xml.key
sudo apt-key add ./repomd.xml.key
sudo apt-key list
sudo apt-get update

Hi @Kurt_Ko

Thanks for the response. Below is the output

[sudo] password for mint:            
OK
mint:~$ cd /tmp
mint:/tmp$ wget https://d2t3ff60b2tol4.cloudfront.net/repomd.xml.key
--2021-01-11 22:09:44--  https://d2t3ff60b2tol4.cloudfront.net/repomd.xml.key
Resolving d2t3ff60b2tol4.cloudfront.net (d2t3ff60b2tol4.cloudfront.net)... 13.32.215.91, 13.32.215.34, 13.32.215.102, ...
Connecting to d2t3ff60b2tol4.cloudfront.net (d2t3ff60b2tol4.cloudfront.net)|13.32.215.91|:443... connected.
HTTP request sent, awaiting response... 200 OK
Length: 965 [application/x-iwork-keynote-sffkey]
Saving to: ‘repomd.xml.key’

repomd.xml.key      100%[===================>]     965  --.-KB/s    in 0s      

2021-01-11 22:09:44 (82.5 MB/s) - ‘repomd.xml.key’ saved [965/965]

mint:/tmp$ sudo apt-key add ./repomd.xml.key
OK
mint:/tmp$ sudo apt-key list
/etc/apt/trusted.gpg
--------------------
pub   rsa1024 2015-11-07 [SC] [expires: 2025-11-04]
      8F20 8FBF 12FE E766 AA32  AEAF 03C3 AD3A 7F06 8E5D
uid           [ unknown] MegaLimited <support@mega.co.nz>
sub   rsa1024 2015-11-07 [E] [expires: 2025-11-04]

pub   rsa1024 2010-12-29 [SC]
      36E8 1C92 67FD 1383 FCC4  4909 83FB A175 1378 B444
uid           [ unknown] Launchpad PPA for LibreOffice Packaging

pub   rsa1024 2013-12-03 [SC]
      A006 2203 196C A448 2DDB  859E 4C1C BE14 8525 41CB
uid           [ unknown] Launchpad PPA for Panda Jim

pub   rsa4096 2020-01-23 [SC]
      BE5E D0F9 261C AAD9 A1E5  B1A4 CD62 89E9 99EA 819D
uid           [ unknown] Launchpad PPA for Jonas Kvinge

pub   rsa4096 2014-01-13 [SCEA] [expired: 2019-01-12]
      418A 7F2F B0E1 E6E7 EABF  6FE8 C2E7 3424 D590 97AB
uid           [ expired] packagecloud ops (production key) <ops@packagecloud.io>

pub   rsa4096 2016-02-18 [SCEA]
      DB08 5A08 CA13 B8AC B917  E0F6 D938 EC0D 0386 51BD
uid           [ unknown] https://packagecloud.io/slacktechnologies/slack (https://packagecloud.io/docs#gpg_signing) <support@packagecloud.io>
sub   rsa4096 2016-02-18 [SEA]

pub   rsa2048 2012-09-10 [SCEA] [expires: 2024-09-08]
      AEEB 94E9 C5A3 B54E CFA4  A66A A684 470C ACCA F35C
uid           [ unknown] Insynchq Inc <services@insynchq.com>

/etc/apt/trusted.gpg.d/brave-browser-release.gpg
------------------------------------------------
pub   rsa4096 2018-10-15 [SC] [expires: 2025-03-17]
      D8BA D4DE 7EE1 7AF5 2A83  4B2D 0BB7 5829 C2D4 E821
uid           [ unknown] Brave Software <support@brave.com>
sub   rsa4096 2019-10-17 [S] [expires: 2022-05-07]

/etc/apt/trusted.gpg.d/nordvpn-keyring.gpg
------------------------------------------
pub   rsa4096 2018-08-02 [SC]
      BC54 80EF EC5C 081C E5BC  FBE2 6B21 9E53 5C96 4CA1
uid           [ unknown] NordVPN <admin@nordvpn.com>
sub   rsa4096 2018-08-02 [S]

/etc/apt/trusted.gpg.d/nordvpn_public.asc
-----------------------------------------
pub   rsa4096 2018-08-02 [SC]
      BC54 80EF EC5C 081C E5BC  FBE2 6B21 9E53 5C96 4CA1
uid           [ unknown] NordVPN <admin@nordvpn.com>
sub   rsa4096 2018-08-02 [S]

/etc/apt/trusted.gpg.d/ubuntu-defaults.chroot.key.gpg
-----------------------------------------------------
pub   rsa4096 2016-05-24 [SC]
      302F 0738 F465 C153 5761  F965 A661 6109 451B BBF2
uid           [ unknown] Linux Mint Repository Signing Key <root@linuxmint.com>
sub   rsa4096 2016-05-24 [E]

/etc/apt/trusted.gpg.d/ubuntu-keyring-2012-archive.gpg
------------------------------------------------------
pub   rsa4096 2012-05-11 [SC]
      790B C727 7767 219C 42C8  6F93 3B4F E6AC C0B2 1F32
uid           [ unknown] Ubuntu Archive Automatic Signing Key (2012) <ftpmaster@ubuntu.com>

/etc/apt/trusted.gpg.d/ubuntu-keyring-2012-cdimage.gpg
------------------------------------------------------
pub   rsa4096 2012-05-11 [SC]
      8439 38DF 228D 22F7 B374  2BC0 D94A A3F0 EFE2 1092
uid           [ unknown] Ubuntu CD Image Automatic Signing Key (2012) <cdimage@ubuntu.com>

/etc/apt/trusted.gpg.d/ubuntu-keyring-2016-dbgsym.gpg
-----------------------------------------------------
pub   rsa4096 2016-03-21 [SC] [expires: 2021-03-20]
      F2ED C64D C5AE E1F6 B9C6  21F0 C8CA B659 5FDF F622
uid           [ unknown] Ubuntu Debug Symbol Archive Automatic Signing Key (2016) <ubuntu-archive@lists.ubuntu.com>

/etc/apt/trusted.gpg.d/ubuntu-keyring-2018-archive.gpg
------------------------------------------------------
pub   rsa4096 2018-09-17 [SC]
      F6EC B376 2474 EDA9 D21B  7022 8719 20D1 991B C93C
uid           [ unknown] Ubuntu Archive Automatic Signing Key (2018) <ftpmaster@ubuntu.com>

mint:/tmp$ sudo apt-get update
Ign:1 http://packages.linuxmint.com ulyssa InRelease
Hit:2 http://packages.linuxmint.com ulyssa Release                             
Get:3 http://security.ubuntu.com/ubuntu focal-security InRelease [109 kB]      
Hit:4 https://brave-browser-apt-release.s3.brave.com stable InRelease          
Hit:5 http://archive.ubuntu.com/ubuntu focal InRelease                         
Hit:6 http://archive.canonical.com/ubuntu focal InRelease                      
Hit:8 https://repo.nordvpn.com//deb/nordvpn/debian stable InRelease            
Err:9 http://apt.insync.io/mint ulyssa InRelease                               
  403  Forbidden [IP: 52.217.86.188 80]
Hit:10 http://ppa.launchpad.net/jonaski/strawberry/ubuntu focal InRelease      
Get:11 http://archive.ubuntu.com/ubuntu focal-updates InRelease [114 kB]       
Hit:13 http://ppa.launchpad.net/libreoffice/ppa/ubuntu focal InRelease         
Hit:14 http://ppa.launchpad.net/ubuntuhandbook1/apps/ubuntu focal InRelease    
Get:15 http://archive.ubuntu.com/ubuntu focal-backports InRelease [101 kB]     
Get:16 https://mega.nz/linux/MEGAsync/xUbuntu_20.04 ./ InRelease [2,441 B]     
Hit:12 https://packagecloud.io/slacktechnologies/slack/debian jessie InRelease 
Get:17 http://archive.ubuntu.com/ubuntu focal-updates/main amd64 DEP-11 Metadata [264 kB]
Get:18 http://archive.ubuntu.com/ubuntu focal-updates/universe amd64 DEP-11 Metadata [281 kB]
Get:19 http://archive.ubuntu.com/ubuntu focal-updates/multiverse amd64 DEP-11 Metadata [2,468 B]
Get:20 http://archive.ubuntu.com/ubuntu focal-backports/universe amd64 DEP-11 Metadata [1,768 B]
Reading package lists... Done                
E: Failed to fetch http://apt.insync.io/mint/dists/ulyssa/InRelease  403  Forbidden [IP: 52.217.86.188 80]
E: The repository 'http://apt.insync.io/mint ulyssa InRelease' is not signed.
N: Updating from such a repository can't be done securely, and is therefore disabled by default.
N: See apt-secure(8) manpage for repository creation and user configuration details.
mint:/tmp$ 

Bump… any further development on this issue?

Hi @affiliatex

Can you send us the output of cat /etc/apt/sources.list.d/insync.list? Thanks!

Got the same issue here when trying to add a Node.JS repository, and I fixed it by commenting out the contents of that file (cat /etc/apt/sources.list.d/insync.list)

The only line in there is:
deb http://apt.insync.io/debian buster non-free contrib

1 Like

Hi @Drakinite :slight_smile: I’ll forward this to our engineers. Thanks for including the fix!

Hi again @Drakinite!! It seems like what you did results in disabling Insync repo updates? :slight_smile: I sought help from our engineers and they advised for users run this script: https://drive.google.com/file/d/1NMkxiO0JmajT1WG2y5AKEq882sJWSmdv/view?usp=drivesdk

The file in the GDrive link is insync_update_key.sh. Download that and run sudo bash [PATH_TO_SCRIPT]. :slight_smile:

1 Like

Hi @mia,
I am also having the problem of the expired repo key.
I am on openSuse so cannot use your engineer’s script (which relies on apt).

Here is what I’m seeing after deleting the expired key and refreshing:

Retrieving repository 'Insync' metadata ------------------------------------------------------------------------------------------------------------------------------------------[\]

New repository or package signing key received:

  Repository:       Insync
  Key Fingerprint:  AEEB 94E9 C5A3 B54E CFA4 A66A A684 470C ACCA F35C
  Key Name:         Insynchq Inc <services@insynchq.com>
  Key Algorithm:    RSA 2048
  Key Created:      Sun Sep 11 18:53:21 2016
  Key Expires:      Thu Sep 10 18:53:07 2020 (EXPIRED)
  Subkey:           06BBDC2602DFE7E7 2012-09-10 [expired: 2020-09-10]
  Rpm Name:         gpg-pubkey-accaf35c-57d58c01

Can you please help?

Thank you in advance
Cris

Hi @Cris70! Apologies for the trouble. Let me check this out with our engineers and update you accordingly.

Hi again @Cris70

Please run sudo rpm -e gpg-pubkey-accaf35c-57d58c01 sudo rpm --import https://d2t3ff60b2tol4.cloudfront.net/repomd.xml.key and let me know how it goes!

Thank you @mia, this time it worked!

1 Like

Wonderful! Thank you for the update @Cris70 :slight_smile:

bug 1: apt-key is deprecated. Source:
even the man page https://manpages.ubuntu.com/manpages/impish/man8/apt-key.8.html says so.

Err:9 http://apt.insync.io/mint ulyssa InRelease
403 Forbidden [IP: 52.217.86.188 80]

That happen for me trying to use Debian bullseye (currently Debian stable) repository which does not exist on insync side. Worked with Debian buster (currently: Debian oldstable).


bug 2: insync bullseye repository does not exist


bug 3: instructions recommend sudo apt-key adv --keyserver keyserver.ubuntu.com --recv-keys ACCAF35C but key is not there. Reference:

go to https://keyserver.ubuntu.com/ and search for key id

ACCAF35C

It’s not there.


bug 4: using short gpg key ids. reference: https://lwn.net/Articles/689792/


bug 5: use of key servers. Old style key servers should be avoided. Reference: https://gist.github.com/rjhansen/67ab921ffb4084c865b3618d6955275f


bug 6: not using APT signed-by. Example:

deb [signed-by=/etc/apt/trusted.gpg.d/insync.asc] http://apt.insync.io/debian buster non-free contrib

I cannot post links as new user. Therefore had to use code tags for my post. Moderators feel free to remove the code tags from my post to make it better readable.

1 Like

@adrelanos Let me check this out with our Linux team! Thank you for the very detailed post. :slight_smile: