Inedo Community Forums Forums
    • Recent
    • Tags
    • Popular
    • Login

    Welcome to the Inedo Forums! Check out the Forums Guide for help getting started.

    If you are experiencing any issues with the forum software, please visit the Contact Form on our website and let us know!

    ProGet: Feed Signing Key

    Scheduled Pinned Locked Moved Support
    5 Posts 2 Posters 21 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S Offline
      stno_9153
      last edited by

      Hi all,

      I want to test ProGet as an APT Proxy for example
      http://security.ubuntu.com/ubuntu/

      The packages downloaded from the ProGet APT Proxy and the original Ubuntu Repositories have the identical md5sum.

      ProGet creates for the feed a special signing key, which I can download with curl at Update archive Usage Instructions.

      I use the feed only for caching. I do not want upload own Debian packages.

      In this special case the packages and the (In)Release files should be mirrored and signed with the original Ubuntu Key.

      Then I can verify the packages with the original Ubuntu key, which is already installed.

      Thank you
      Stefan

      atrippA 1 Reply Last reply Reply Quote 0
      • atrippA Offline
        atripp inedo-engineer @stno_9153
        last edited by

        Hi @stno_9153 ,

        (In)Release files are signed using a private/public key scheme, so unless you were somehow able to get a copy of Ubuntu's private signing keys and upload it to ProGet... it is not possible to sign those files using the original Ubuntu Key.

        Cheers,
        Alana

        1 Reply Last reply Reply Quote 0
        • S Offline
          stno_9153
          last edited by

          Hi Alana,

          various tools for example debmirror are syncing and using the orginal (In)Release files from the debian mirror and do not sign the (In)Release files.

          Therefore the packages from my old Debian Repository Server with debmirror can be validated by the Public Ubuntu Signing Key.

          Thanks Stefan

          atrippA 1 Reply Last reply Reply Quote 0
          • atrippA Offline
            atripp inedo-engineer @stno_9153
            last edited by

            Hi @stno_9153 ,

            Thanks for clarifying; that's not possible with ProGet. A Debian feed is not designed to be a "read-only mirror", but instead a repository where you can add/filter/update packages. So, that's why ProGet must generate/sign the (In)Release files.

            I'm afraid we have no plans to support a read-only mirror use case in the forseeable future.

            Cheers,
            Alana

            1 Reply Last reply Reply Quote 0
            • S Offline
              stno_9153
              last edited by

              Hi Alana,
              thank you for your reply

              1 Reply Last reply Reply Quote 0

              Hello! It looks like you're interested in this conversation, but you don't have an account yet.

              Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

              With your input, this post could be even better 💗

              Register Login
              • 1 / 1
              • First post
                Last post
              Inedo Website Home • Support Home • Code of Conduct • Forums Guide • Documentation