镜像站点 · 本页由第三方 GitHub 只读镜像提供,非 GitHub 官方站点,不接受任何登录或凭据输入。前往 github.com
Skip to content

Unable to Verify Signature of Version 10.23.0 #35850

Description

@patrickbucher
  • Version: 10.23.0:
  • Platform: Linux 64-bit:

What steps will reproduce the bug?

Running the following script:

#!/usr/bin/bash

curl -O https://nodejs.org/dist/v10.23.0/SHASUMS256.txt
curl -O https://nodejs.org/dist/v10.23.0/SHASUMS256.txt.sig
gpg --verify SHASUMS256.txt.sig SHASUMS256.txt

Causes this error message:

gpg: Signature made Tue 27 Oct 2020 05:02:23 PM CET
gpg:                using RSA key C43CEC45C17AB93C
gpg: Can't check signature: No public key

How often does it reproduce? Is there a required condition?

It always happens

What is the expected behavior?

The verification should work.

What do you see instead?

see error message above

Additional information

The RSA key C43CEC45C17AB93C cannot be obtained through keyserver.ubuntu.com

Activity

  1. aduh95 commented on Oct 28, 2020

    @aduh95
    Contributor

    @nodejs/releasers

  2. richardlau commented on Oct 28, 2020

    @richardlau
    Member

    I uploaded my key to the sks-keyservers.net pool (as per the recommendation) months ago (#34397 (review)). I have no idea if keyserver.ubuntu.com is in that pool for it to replicate across but if it isn't then you're not going to be guaranteed to find the release keys there.

    FWIW I've manually sent my key to keyserver.ubuntu.com so it should be found there now.

  3. patrickbucher commented on Oct 28, 2020

    @patrickbucher
    Author

    @richardlau Thanks, that worked fine!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions