Arch Linux

Please read this before reporting a bug:
https://wiki.archlinux.org/title/Bug_reporting_guidelines

Do NOT report bugs when a package is just outdated, or it is in the AUR. Use the 'flag out of date' link on the package page, or the Mailing List.

REPEAT: Do NOT report bugs for outdated packages!
Tasklist

FS#75957 - importing new keys or refreshing keys don't work with pacman-key

Attached to Project: Arch Linux
Opened by Berin Aniesh (berinaniesh) - Tuesday, 20 September 2022, 12:04 GMT
Last edited by Toolybird (Toolybird) - Thursday, 22 September 2022, 00:57 GMT
Task Type Bug Report
Category Packages: Core
Status Closed
Assigned To No-one
Architecture All
Severity Low
Priority Normal
Reported Version
Due in Version Undecided
Due Date Undecided
Percent Complete 100%
Votes 0
Private No

Details

Description:
Can't import keys with archlinux-keyring

Additional info:
Error:
pg: error retrieving 'arch@eworm.de' via WKD: Server indicated a failure
gpg: error reading key: Server indicated a failure
gpg: error retrieving 'eworm@archlinux.org' via WKD: Server indicated a failure
gpg: error reading key: Server indicated a failure
gpg: refreshing 1 key from hkps://keyserver.ubuntu.com
gpg: keyserver refresh failed: Server indicated a failure
==> ERROR: Could not update key: A6234074498E9CEE
gpg: error retrieving 'george@rawlinson.net.nz' via WKD: Server indicated a failure
gpg: error reading key: Server indicated a failure
gpg: error retrieving 'grawlinson@archlinux.org' via WKD: Server indicated a failure
gpg: error reading key: Server indicated a failure
gpg: refreshing 1 key from hkps://keyserver.ubuntu.com
gpg: keyserver refresh failed: Server indicated a failure
==> ERROR: Could not update key: 25EA6900D9EA5EBC


Steps to reproduce:
Make a new arch linux installation, try importing a key or refreshing the existing keys with `pacman-key --refresh-kes`.
This task depends upon

Closed by  Toolybird (Toolybird)
Thursday, 22 September 2022, 00:57 GMT
Reason for closing:  Not a bug
Additional comments about closing:  See comments
Comment by Toolybird (Toolybird) - Thursday, 22 September 2022, 00:57 GMT
I'm not sure why anyone would ever need to run `pacman-key --refresh-keys`. I know it's mentioned in the wiki [1] but manually updating "archlinux-keyring" is always a better option. There is also the problem on fresh installs where you have to wait for "pacman-init" to finish [2].

Anyway, I just tried it in a VM and the results were not pleasing. It takes ages and I saw the same WKD: errors as above. But in my test it then moved on to the Ubuntu keyserver and successfully refreshed each key. It your case above, you were getting the WKD: errors *plus* it appears the Ubuntu server was also failing. I'm putting this down to network flakiness at the time you ran it.

AFAIK, the Arch WKD setup is still being tweaked.

[1] https://gitlab.archlinux.org/archlinux/archiso/-/issues/191
[2] https://wiki.archlinux.org/title/Pacman/Package_signing#Signature_is_unknown_trust

Loading...