OpenPrinting Release.gpg - bad signature.

Bug #1365930 reported by DiagonalArg
12
This bug affects 2 people
Affects Status Importance Assigned to Milestone
foomatic-db (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

I have repeated this download 3 times including cutting and pasting from the web page:

@ThinkPad-T61p:~/temp$ curl -O https://www.openprinting.org/download/printdriver/debian/dists/lsb3.2/Release.gpg
  % Total % Received % Xferd Average Speed Time Time Time Current
                                 Dload Upload Total Spent Left Speed
100 490 100 490 0 0 949 0 --:--:-- --:--:-- --:--:-- 1186

@ThinkPad-T61p:~/temp$ curl -O https://www.openprinting.org/download/printdriver/debian/dists/lsb3.2/Release
  % Total % Received % Xferd Average Speed Time Time Time Current
                                 Dload Upload Total Spent Left Speed
100 5165 100 5165 0 0 20322 0 --:--:-- --:--:-- --:--:-- 31687

In every case, I get the same result:

@ThinkPad-T61p:~/temp$ sudo gpg --keyring /etc/apt/trusted.gpg --verify Release.gpg Release

gpg: Signature made Mon 31 Mar 2014 05:13:54 AM PDT using RSA key ID 4CFD1E2F
gpg: BAD signature from "OpenPrinting (OpenPrinting Key) <email address hidden>"

I do have the proper key, and I've even updated from the keyserver:

@ThinkPad-T61p:~/temp$ sudo gpg --keyring /etc/apt/trusted.gpg --list-keys | grep 4CFD1E2F
pub 2048R/4CFD1E2F 2013-02-27

Ubuntu 12.04

Tags: openprinting
Revision history for this message
DiagonalArg (diagonalarg) wrote :

This problem initially appeared when running "sudo apt-get update":

Reading package lists... Done
W: GPG error: file: lsb3.2 Release: The following signatures were invalid: BADSIG 24CBF5474CFD1E2F OpenPrinting (OpenPrinting Key) <email address hidden>

I chased it down and discovered it's not an old or missing key. The signature is actually bad.

Revision history for this message
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in foomatic-db (Ubuntu):
status: New → Confirmed
Revision history for this message
Till Kamppeter (till-kamppeter) wrote :

I have tried to reproduce it and do not run into any "Bad Signature" problem:

till@till-twist:~$ curl -O https://www.openprinting.org/download/printdriver/debian/dists/lsb3.2/Release.gpg
  % Total % Received % Xferd Average Speed Time Time Time Current
                                 Dload Upload Total Spent Left Speed
100 490 100 490 0 0 392 0 0:00:01 0:00:01 --:--:-- 393
till@till-twist:~$ curl -O https://www.openprinting.org/download/printdriver/debian/dists/lsb3.2/Release
  % Total % Received % Xferd Average Speed Time Time Time Current
                                 Dload Upload Total Spent Left Speed
100 5165 100 5165 0 0 5145 0 0:00:01 0:00:01 --:--:-- 5149
till@till-twist:~$ sudo gpg --keyring /etc/apt/trusted.gpg --verify Release.gpg Release
gpg: WARNING: unsafe ownership on configuration file `/home/till/.gnupg/gpg.conf'
gpg: Signature made Mi 10 Sep 2014 20:08:22 CEST using RSA key ID 4CFD1E2F
gpg: Good signature from "OpenPrinting (OpenPrinting Key) <email address hidden>"
gpg: WARNING: This key is not certified with a trusted signature!
gpg: There is no indication that the signature belongs to the owner.
Primary key fingerprint: F889 7B6F 0007 5648 E248 B7EC 24CB F547 4CFD 1E2F
till@till-twist:~$ sudo gpg --keyring /etc/apt/trusted.gpg --list-keys | grep 4CFD1E2F
gpg: WARNING: unsafe ownership on configuration file `/home/till/.gnupg/gpg.conf'
pub 2048R/4CFD1E2F 2013-02-27
pub 2048R/4CFD1E2F 2013-02-27
till@till-twist:~$

Revision history for this message
DiagonalArg (diagonalarg) wrote :

@Till - thank you for checking. I have just done an apt-get update, and the problem did not appear. I repeated the process that you had kindly checked, _without_ downloading the key again, and now I am not finding the bad signature. The only answer can be that temporarily there was a bad signature. (I did email the webmaster at openprinting.org about this issue a few days prior to posting this bug, so perhaps the issue was corrected there?)

Revision history for this message
DiagonalArg (diagonalarg) wrote :

This appears to be the same as this bug:

https://answers.launchpad.net/ubuntu/+question/253803

Changed in foomatic-db (Ubuntu):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.