Thursday, May 24, 2018

security - How to identify and remove unused apt keys?

On a typical installation several apt GPG keys are added, be it for PPAs or other sources, and later go unused.



It is hard to identify in the GUI (software-properties) which keys are actually used for which repositories.



Is there an easy way to identify which keys are used at all, so that all the other keys can be removed?



In my opinion this has some security implications. If a repository owner loses their private key and updates the repository to use a new key, lots of people still have the old (non trustworthy) key installed, right?

No comments:

Post a Comment

11.10 - Can't boot from USB after installing Ubuntu

I bought a Samsung series 5 notebook and a very strange thing happened: I installed Ubuntu 11.10 from a usb pen drive but when I restarted (...