You are not logged in.

#1 2019-12-29 09:05:14

XiaoaiX
Member
Registered: 2016-01-03
Posts: 10

The aurman package can not be verified

I download the PKGBUILD file for the aurman and use makepkg to install it, and it shows

==> Validating source files with md5sums...
    aurman_sources ... Skipped
==> Verifying source file signatures with gpg...
    aurman_sources git repo ... FAILED (unknown public key 465022E743D71E39)
==> ERROR: One or more PGP signatures could not be verified!

I then tried

sudo pacman-key --recv-keys 465022E743D71E39

it shows,

gpg: keyserver receive failed: Server indicated a failure
==> ERROR: Remote key not fetched correctly from keyserver.

I also tried

$gpg --keyserver hkps://hkps.pool.sks-keyservers.net --search-keys 465022E743D71E39

it shows

gpg: error searching keyserver: Server indicated a failure
gpg: keyserver search failed: Server indicated a failure

Does this mean that this package is not trustworthy?
I am using pool.sks-keyservers.net as the keyserver.

Offline

#2 2019-12-29 09:12:42

XiaoaiX
Member
Registered: 2016-01-03
Posts: 10

Re: The aurman package can not be verified

I finally noticed the comment from polygamma,

aurman development for public use has been stopped. i suggest migrating to yay, i am not interested in any kind of feedback, bug reports, feature requests etc. anymore.

So, it seems that aurman was also discontinued.

Offline

#3 2019-12-29 13:58:29

Trilby
Inspector Parrot
Registered: 2011-11-29
Posts: 30,525
Website

Re: The aurman package can not be verified

wiki wrote:

Note: The signature checking implemented in makepkg does not use pacman's keyring, instead relying on the user's keyring.

https://wiki.archlinux.org/index.php/Ma … e_checking

EDIT: I see you did search the key server later - but note that you should not use pacman-key for AUR sigs.

Last edited by Trilby (2019-12-29 14:00:43)


"UNIX is simple and coherent" - Dennis Ritchie; "GNU's Not Unix" - Richard Stallman

Offline

#4 2019-12-30 05:20:36

eschwartz
Fellow
Registered: 2014-08-08
Posts: 4,097

Re: The aurman package can not be verified

XiaoaiX wrote:

Does this mean that this package is not trustworthy?

No... it means that your GnuPG installation had internet trouble, therefore you could not look up the AUR package's signature to see whether it is trustworthy or not.

The solution to this problem is that your GnuPG installation needs to be fixed. Your thread title is misleading -- it implies you are having a problem with a specific AUR package, when you are really having a problem with GnuPG (and this issue would apply to *all* packages you tried to build that use GnuPG).

...

If it helps, I've always found gpg --keyserver keyserver.ubuntu.com to always be quite reliable.

I am using pool.sks-keyservers.net as the keyserver.

The thing about pool.sks-keyservers.net is that it isn't actually a keyserver. It's a way of autoselecting a keyserver based on location, but sometimes it returns broken keyservers.


Managing AUR repos The Right Way -- aurpublish (now a standalone tool)

Offline

Board footer

Powered by FluxBB