From mboxrd@z Thu Jan 1 00:00:00 1970 X-GM-THRID: 7219175689105178624 X-Received: by 2002:a05:6830:1e43:b0:6a4:2e3a:6e40 with SMTP id e3-20020a0568301e4300b006a42e3a6e40mr10192otj.0.1681316529218; Wed, 12 Apr 2023 09:22:09 -0700 (PDT) X-BeenThere: isar-users@googlegroups.com Received: by 2002:a05:6808:1a1e:b0:38b:f327:30dd with SMTP id bk30-20020a0568081a1e00b0038bf32730ddls559534oib.4.-pod-prod-gmail; Wed, 12 Apr 2023 09:22:08 -0700 (PDT) X-Google-Smtp-Source: AKy350btnrbwjeOU1unSIiwO356YxdDv1/bPxHQHqjQoubufh39+Y/rXLFx2xEIvaEHxT6GXOyYY X-Received: by 2002:a05:6808:488:b0:389:72d5:f160 with SMTP id z8-20020a056808048800b0038972d5f160mr7876724oid.30.1681316528436; Wed, 12 Apr 2023 09:22:08 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1681316528; cv=none; d=google.com; s=arc-20160816; b=NSa0MrPiwFz/EqV6JHFd+fhifFfHJHUQ2blSdtjjv3Pg9QAv+sW0+bOPWGyGsg7cLP OPhAfWE8AEBkAxGik9soO1V2SoSUpp+ImmV4fMwRuffABPjD/r3TwuLd03jb8V9JC+ES V+dzza/5F5i+IPuNT/vWUXodi2k/Z3wg+WgN4hpDwfwuIAqNIuQ764MBouwtLWmKqP3q WQr4cBqrThiEkyvPW4hjBjrPX74gw+DXnl1U+Firw0SSBdyydtUFFb5d4YvAPlKWBdt0 3shOFD+pyw9A5g3X2AzErDtBCkavmMIDpjaE0sMGwZLQZOXNlwF/8A/Q3kFDfSGm2b3O izxQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:to:from; bh=KJPjIUW6h98/EGJVUvMONEiT/CLJjPwvQXi4eqJm+Wo=; b=dr2JWUszqr820j7pEXPWye5fKOT6uesaSN8kYQAT4PLRIlAMtc+YiPvr5WBxmLDuGy klhtEmGTt//Va+yisFRiUeJqTPaovFgK9gLCY8n0FnfyVte+dx13+wRdABdf5DxtZXZg 18s97tO0/riTgs41nREYsWdToRWK0qQhkKiFc3OmkwgdT3C5xGUm7tPyjbS+7uSVkZMJ hXsLSti/P3HQMs0nlAtB9IIwQ0q4jsNOySGjXFHogLqu7sWR4S+say/2HSrNLIVtsuow d5yq/8Zd/VqnKUB9oeq6fVx0Zf1LpxcIBIJ+UisN+cvXUc2VVLO0JoODh4DhRYN1PYpV csPw== ARC-Authentication-Results: i=1; gmr-mx.google.com; spf=pass (google.com: domain of ubely@ilbers.de designates 85.214.156.166 as permitted sender) smtp.mailfrom=ubely@ilbers.de Return-Path: Received: from shymkent.ilbers.de (shymkent.ilbers.de. [85.214.156.166]) by gmr-mx.google.com with ESMTPS id x6-20020a056808144600b0038beee55b0csi142690oiv.5.2023.04.12.09.22.07 for (version=TLS1_2 cipher=ECDHE-ECDSA-CHACHA20-POLY1305 bits=256/256); Wed, 12 Apr 2023 09:22:08 -0700 (PDT) Received-SPF: pass (google.com: domain of ubely@ilbers.de designates 85.214.156.166 as permitted sender) client-ip=85.214.156.166; Authentication-Results: gmr-mx.google.com; spf=pass (google.com: domain of ubely@ilbers.de designates 85.214.156.166 as permitted sender) smtp.mailfrom=ubely@ilbers.de Received: from hp.localnet (host-80-81-17-52.static.customer.m-online.net [80.81.17.52]) (authenticated bits=0) by shymkent.ilbers.de (8.15.2/8.15.2/Debian-8+deb9u1) with ESMTPSA id 33CGM5ML000389 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for ; Wed, 12 Apr 2023 18:22:06 +0200 From: Uladzimir Bely To: isar-users@googlegroups.com Subject: Re: [PATCH] meta-isar: Add local ubuntu-focal public key Date: Wed, 12 Apr 2023 19:22:03 +0300 Message-ID: <2657096.vuYhMxLoTh@hp> In-Reply-To: <20230407052838.24924-1-ubely@ilbers.de> References: <20230407052838.24924-1-ubely@ilbers.de> MIME-Version: 1.0 Content-Transfer-Encoding: 7Bit Content-Type: text/plain; charset="us-ascii" X-Spam-Status: No, score=-1.0 required=5.0 tests=ALL_TRUSTED autolearn=unavailable autolearn_force=no version=3.4.2 X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on shymkent.ilbers.de X-TUID: 4OHgmqGCEmm9 In mail from Friday, 7 April 2023 08:28:38 +03 user Uladzimir Bely wrote: > When debootstrapping Ubuntu in signed mode we need a local key > taken from official Ubuntu repository, similar to RaspiOS. > > This makes debootstrapping more strict and additionally allows to use > other debootstrapping utilities (like mmdebstrap). > > Signed-off-by: Uladzimir Bely > --- > Debootstrap log before the patch: > > ``` > I: Running command: debootstrap --verbose --variant=minbase > --include=locales --arch=amd64 > --components=main,restricted,universe,multiverse focal > /build/tmp/work/ubuntu-focal-amd64/isar-bootstrap-target/1.0-r0/rootfs > http://archive.ubuntu.com/ubuntu /usr/share/debootstrap/scripts/gutsy W: > Cannot check Release signature; keyring file not available > /usr/share/keyrings/ubuntu-archive-keyring.gpg I: Retrieving InRelease > I: Retrieving Packages > ``` > Debootstrap log after the patch: > > ``` > I: Running command: debootstrap --verbose --variant=minbase > --include=locales,gnupg > --keyring=/build/tmp/work/ubuntu-focal-amd64/isar-bootstrap-target/1.0-r0/d > istro-keyring.gpg --arch=amd64 > --components=main,restricted,universe,multiverse focal > /build/tmp/work/ubuntu-focal-amd64/isar-bootstrap-target/1.0-r0/rootfs > http://archive.ubuntu.com/ubuntu /usr/share/debootstrap/scripts/gutsy I: > Retrieving InRelease > I: Checking Release signature > I: Valid Release signature (key id F6ECB3762474EDA9D21B7022871920D1991BC93C) > I: Retrieving Packages > ``` > > meta-isar/conf/distro/ubuntu-focal.conf | 5 +++ > meta-isar/conf/distro/ubuntu.public.key | 53 +++++++++++++++++++++++++ > 2 files changed, 58 insertions(+) Applied to next.