The following happened to me today:

colan@somewhere[Tue 11 21:15]% sudo apt update; sudo apt full-upgrade                                                                             
Get:1 http://debian.aegirproject.org unstable InRelease [3,142 B]                   
Get:2 http://security.ubuntu.com/ubuntu xenial-security InRelease [94.5 kB]                                      
Err:1 http://debian.aegirproject.org unstable InRelease                                                                    
  The following signatures were invalid: KEYEXPIRED 1476206881  KEYEXPIRED 1476206881  KEYEXPIRED 1476206881
[...]
W: An error occurred during the signature verification. The repository is not updated and the previous index files will be used. GPG error: http://debian.aeg
irproject.org unstable InRelease: The following signatures were invalid: KEYEXPIRED 1476206881  KEYEXPIRED 1476206881  KEYEXPIRED 1476206881
W: Failed to fetch http://debian.aegirproject.org/dists/unstable/InRelease  The following signatures were invalid: KEYEXPIRED 1476206881  KEYEXPIRED 14762068
81  KEYEXPIRED 1476206881
W: Some index files failed to download. They have been ignored, or old ones used instead.

Get the renewed key ...

curl http://debian.aegirproject.org/key.asc | sudo apt-key add -
sudo apt-get update

Comments

colan created an issue. See original summary.

NWOM’s picture

I'm running into the same issue, since this morning. This also occurs with the stable branch.

NWOM’s picture

As a workaround, I installed aegir3 with the parameter "--force=yes"

helmo’s picture

we need a check for that ... last time ... #2110057: Key used for signing debian package has expired

I'll update it.

helmo’s picture

Issue summary: View changes

I've renewed the key.

Steps to update on servers using these packages:

curl http://debian.aegirproject.org/key.asc | sudo apt-key add -
sudo apt-get update
helmo’s picture

Status: Active » Fixed
helmo’s picture

Documenting for a next time ...

reprepro@zeus:~$ gpg --edit-key 3376CCF9

gpg> expire
Changing expiration time for the primary key.        
Please specify how long the key should be valid.  
         0 = key does not expire                              
      <n>  = key expires in n days                         
      <n>w = key expires in n weeks                            
      <n>m = key expires in n months                           
      <n>y = key expires in n years                          
Key is valid for? (0) 3y
Key expires at Sat 12 Oct 2019 09:12:54 AM EDT             
Is this correct? (y/N) y                                               
gpg> save

gpg --armor --export 3376CCF9 > key.asc

I've also opened a meta issue to discuss #2817199: Alternative hosting of the Debian package archive

colan’s picture

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.

helmo’s picture

I've now added a copy of the public key to Git. That way there is a way to verify the file on http://debian.aegirproject.org/key.asc

And the documentation from #7 is now on http://docs.aegirproject.org/en/3.x/community/release-process/debian-pac...

joshrabinowitz’s picture

Looks like this is about to happen again... expires Oct 12 2019

joshrabinowitz’s picture

Any chance you could renew the key before it expires? https://docs.aegirproject.org/en/3.x/community/release-process/ 404s, but I found a version from 2018:

https://web.archive.org/web/20181228184557/http://docs.aegirproject.org/...

helmo’s picture

Thanks for the extra notify @joshrabinowitz

The docs moved a little:
https://docs.aegirproject.org/develop/debian-packaging/
https://docs.aegirproject.org/community/release-process/

I've now opened a new issue to address this.

millenniumtree’s picture

It takes me an hour to find this every time it happens. If google brings you here from a search for the KEYEXPIRED error...

The solution is to:

apt install aegir-archive-keyring
apt update

moss.dev’s picture

Hi all, I am getting the key has expired again.

Even when I pull a new key that key is already expired.

Please can someone deploy a new valid key?

Many thanks,
Jon

SocialNicheGuru’s picture

I am in the same boat. I am also trying to upgrade from ubuntu 20.004 to 22.04 LTS and this issue is stopping the upgrade