You are not logged in.

#1 2018-01-08 19:55:35

olive
Member
From: Belgium
Registered: 2008-06-22
Posts: 1,490

Confused about pacman signing.

I have read the wiki but I am still confused. The wiki seems to say that I have to run "pacman-key --init" but I have never done such thing and nevertheless, it seems that it works. The install wiki does not mention it. Has it been run implicitly by one of the install scripts initially?

On one occasion, pacman asked me to import a developer key. Does it not normally happen automatically?

Last edited by olive (2018-01-08 19:59:30)

Offline

#2 2018-01-09 13:28:02

Lone_Wolf
Member
From: Netherlands, Europe
Registered: 2005-10-04
Posts: 11,911

Re: Confused about pacman signing.

Has it been run implicitly by one of the install scripts initially?

A keyring is normally added to the livecd during the creation of the installation iso.
When you run pacstrap from the installation iso, it will copy the installation iso keyring to to the target if the target doesn't have one.

Last edited by Lone_Wolf (2018-01-09 13:29:02)


Disliking systemd intensely, but not satisfied with alternatives so focusing on taming systemd.


(A works at time B)  && (time C > time B ) ≠  (A works at time C)

Offline

#3 2018-01-09 13:49:04

WorMzy
Forum Moderator
From: Scotland
Registered: 2010-06-16
Posts: 11,845
Website

Re: Confused about pacman signing.

On one occasion, pacman asked me to import a developer key. Does it not normally happen automatically?

There is often a race condition between the archlinux-keyring package and packages signed by new keys (often from a new TU). Because the archlinux-keyring is a core package, it needs to go through testing, but other packages (particularly in community) can be pushed straight into the live repos. When one of these new-key signed packages reaches your system before the new keyring is installed, pacman will explicitly ask you to import the key. Since the key is trusted by the web-of-trust, no other action is needed. If the key isn't trusted by the web-of-trust, then there is a problem and pacman will refuse to install the packages signed by that key (unless you've configured pacman to behave otherwise).


Sakura:-
Mobo: MSI MAG X570S TORPEDO MAX // Processor: AMD Ryzen 9 5950X @4.9GHz // GFX: AMD Radeon RX 5700 XT // RAM: 32GB (4x 8GB) Corsair DDR4 (@ 3000MHz) // Storage: 1x 3TB HDD, 6x 1TB SSD, 2x 120GB SSD, 1x 275GB M2 SSD

Making lemonade from lemons since 2015.

Offline

Board footer

Powered by FluxBB