ubuntu 创建本地deb软件包时,对Release文件做gpg签名
Ubuntu 16.04 (xenial) 在将本地deb软件包创建repo时候,跟14.04以前的版本相比,强制要求gpg对Release文件签名,否则无法使用: Reading package lists... Done
1.1 GPG 创建的密匙,可供加密文件及签名文件使用, 也可创建专供签名文件使用的密匙。 # apt-get install rng-tools # rngd -r /dev/urandom #gpg --gen-key gpg (GnuPG) 1.4.20; Copyright (C) 2015 Free Software Foundation,Inc. This is free software: you are free to change and redistribute it. There is NO WARRANTY,to the extent permitted by law. Please select what kind of key you want: (1) RSA and RSA (default) (2) DSA and Elgamal (3) DSA (sign only) (4) RSA (sign only) Your selection? 4 RSA keys may be between 1024 and 4096 bits long. What keysize do you want? (2048) 2048 Requested keysize is 2048 bits Please specify how long the key should be valid. 0 = key does not expire <n> = key expires in n days <n>w = key expires in n weeks <n>m = key expires in n months <n>y = key expires in n years Key is valid for? (0) Key does not expire at all Is this correct? (y/N) y You need a user ID to identify your key; the software constructs the user ID from the Real Name,Comment and Email Address in this form: "Heinrich Heine (Der Dichter) <heinrichh@duesseldorf.de>" Real name: Ubuntu Local Archive Automatic Signing Key Email address: mac@ispc.cn Comment: 2017 You selected this USER-ID: "Ubuntu Local Archive Automatic Signing Key (2017) <mac@ispc.cn>" Change (N)ame,(C)omment,(E)mail or (O)kay/(Q)uit? o You need a Passphrase to protect your secret key. gpg: gpg-agent is not available in this session We need to generate a lot of random bytes. It is a good idea to perform some other action (type on the keyboard,move the mouse,utilize the disks) during the prime generation; this gives the random number generator a better chance to gain enough entropy. ......+++++ +++++ gpg: key 7A1E912A marked as ultimately trusted public and secret key created and signed. gpg: checking the trustdb gpg: 3 marginal(s) needed,1 complete(s) needed,PGP trust model gpg: depth: 0 valid: 2 signed: 0 trust: 0-,0q,0n,0m,0f,2u pub 4096R/7A1E912A 2017-03-15 Key fingerprint = A11A 69B7 15AB B83A C6AC 4282 02FE 7153 F5A2 4A14 uid Ubuntu Local Archive Automatic Signing Key (2017) <mac@ispc.cn 1.2 导出gpg公钥和私钥,并放到可下载的地方,比如某个web # gpg --list-key # gpg -k /root/.gnupg/pubring.gpg ------------------------ pub 4096R/7A1E912A 2017-03-02 [expires: 2022-03-01] uid Ubuntu Local Archive Automatic Signing Key (2017) <mac@ispc.cn> # gpg -a --export 7A1E912A > Ubuntu_Local_Archive_Automatic_Signing_Key_2017.pub # gpg -a --export-secret-keys 7A1E912A > Ubuntu_Local_Archive_Automatic_Signing_Key_2017.sec 2. 创建Package file # rm -f Packages.gz Packages # apt-ftparchive packages . | gzip -9c > Packages.gz # gunzip -k Packages.gz 使用下面这种internet上常见的方式,必须先安装dpkg-dev软件包, 与使用apt-ftparchive 方式,可一样达到目的,但apt-ftparchive是系统默认已经安装的软件包,不需要再安装,个人认为有优势
# apt-ftparchive release ./ > Release # gpg -abs --default-key 7A1E912A -o Release.gpg Release # gpg --clearsign --default-key 7A1E912A -o InRelease Release 4. 对release file签名 # gpg -abs --default-key 7A1E912A -o Release.gpg Release # gpg --clearsign --default-key 7A1E912A -o InRelease Release 5. 修改ubuntu client sources.list # echo "deb [arch=amd64] http://10.245.254.93/linux/ubuntu/updates/xenial ./" >> /etc/apt/sources.list 6. 下载并导入给release file 签名的公钥 #wget http://10.245.254.93/linux/ubuntu/updates/gpg/Ubuntu_Local_Archive_Automatic_Signing_Key_2017.pub # apt-key add Ubuntu_Local_Archive_Automatic_Signing_Key_2017.pub 7. 可以使用了
解决办法: 最后,只需要下面简单步骤: 在给Releases文件签名前,修改~/.gnupg/gpg.conf,定义参数personal-digest-preferences(the digest used for signing messages)为SHA256。 # echo "personal-digest-preferences SHA256" >> ~/.gnupg/gpg.conf # gpg -abs --default-key 7A1E912A -o Release.gpg Release also can use gpg command option,example: # gpg -abs --default-key 7A1E912A --personal-digest-preferences SHA256 -o Release.gpg Release ----------------------------- 8.1 Server site wget http://10.245.254.93/linux/ubuntu/updates/gpg/Ubuntu_Local_Archive_Automatic_Signing_Key_2017.sec gpg --import Ubuntu_Local_Archive_Automatic_Signing_Key_2017.sec echo "personal-digest-preferences SHA256" >> ~/.gnupg/gpg.conf mkdir /opt/xenial cp -rp /var/cache/apt/archives /opt/xenial cd /opt/xenial rm -rf Packages.gz Packages archives/lock archives/partial apt-ftparchive packages . | gzip -9c > Packages.gz gunzip -k Packages.gz apt-ftparchive release ./ > Release gpg -abs --default-key 7A1E912A --passphrase YourPasswd -o Release.gpg Release gpg --clearsign --default-key 7A1E912A --passphrase YourPasswd -o InRelease Release echo "deb [arch=amd64] file:///opt/xenial ./" >> /etc/apt/sources.list apt-get update
echo "deb [arch=amd64] http://10.245.254.93/linux/ubuntu/updates/xenial ./" >> /etc/apt/sources.list wget http://10.245.254.93/linux/ubuntu/updates/gpg/Ubuntu_Local_Archive_Automatic_Signing_Key_2017.pub apt-key add Ubuntu_Local_Archive_Automatic_Signing_Key_2017.pub apt-get update 补充:ubuntu apt-get 对软件包索引,首先要求InRelease文件,其次才去找Release、Release.gpg文件; 这情况下, 其实只需要创建InRelease文件(包含Release文件和明文签名)即可: # gpg --clearsign --default-key 7A1E912A --passphrase YourPasswd -o InRelease Release 转载地址: https://my.oschina.net/u/3362827/blog/860711 (编辑:台州站长网) 【声明】本站内容均来自网络,其相关言论仅代表作者个人观点,不代表本站立场。若无意侵犯到您的权利,请及时与联系站长删除相关内容! |