| Bug #119212 | Expired GPG signature key for package repository | ||
|---|---|---|---|
| Submitted: | 22 Oct 20:56 | ||
| Reporter: | Emerson Silva | Email Updates: | |
| Status: | Open | Impact on me: | |
| Category: | MySQL Package Repos | Severity: | S2 (Serious) |
| Version: | >= 8.0.36 | OS: | Linux |
| Assigned to: | CPU Architecture: | x86 | |
| Tags: | gpg, repository, signature | ||
[22 Oct 20:56]
Emerson Silva
[23 Oct 14:08]
Marc Hassan
The key link in the description is broken (it has an extra slash at the end). It should be https://repo.mysql.com/RPM-GPG-KEY-mysql-2023.
[23 Oct 15:10]
Eugene Gubenkov
It looks like this key was already updated on Ubuntu keyserver: https://keyserver.ubuntu.com/pks/lookup?search=B7B3B788A8D3785C&fingerprint=on&op=index So the workaround here is to receive the GPG key from the Ubuntu keyserver directly instead of letting "mysql-apt-config" configure it. New expiration date is set to 2027-10-23T12:03:47Z.
[24 Oct 4:25]
Eugene Gubenkov
It looks like new mysql-apt-config is available that embeds a key with updated expiration date (mysql-apt-config_0.8.35-1_all.deb) at https://dev.mysql.com/get/mysql-apt-config_0.8.35-1_all.deb. It addresses the issue for me.
[24 Oct 12:26]
Dayo Lasode
Any idea when https://repo.mysql.com/ will be updated with the new GPG key?
[24 Oct 12:29]
Eugene Gubenkov
Dayo Lasode, There is no need to update the repository key itself. What was needed is updated expiration for the existing one. It is already happened. mysql-apt-config package was also updated and GPG with updated expiration is now embedded. Key/fingerprint is the same.
[24 Oct 12:51]
Dayo Lasode
Hi Eugene This might be specific in my case but our automation pulls the key directly from https://repo.mysql.com/RPM-GPG-KEY-mysql-2023, which is the current latest one but that still shows as expired? ~$ sudo curl -fsSL https://repo.mysql.com/RPM-GPG-KEY-mysql-2023 -o /tmp/fresh.asc -H "Cache-Control: no-cache" ~$ gpg --show-keys /tmp/fresh.asc pub rsa4096 2023-10-23 [SC] [expired: 2025-10-22] BCA43417C3B485DD128EC6D4B7B3B788A8D3785C uid MySQL Release Engineering <mysql-build@oss.oracle.com> sub rsa4096 2023-10-23 [E] [expired: 2025-10-22]
[24 Oct 13:31]
Eugene Gubenkov
Hey Dayo Lasode, Yes, they did not update by this link. However, you can download updated at from Ubuntu key server already.
