GPG

YUM GPG keys

NOTE: If you installed seccubus/latest with our Bash script, Chef cookbook, or Puppet module the GPG key is automatically installed. There is nothing additional you need to do.

GPG signature info

seccubus/latest has its YUM metadata signed with seccubus-latest-A4DB23E1A7E9B462.pub.gpg.

Important notes

There are two types of GPG keyrings used on RPM-based systems:

  1. RPM's GPG keyring. This keyring is used for verifying signatures on RPM packages.
  2. YUM's GPG keyring. This keyring is used for verifying signatures on repository metadata. There is one keyring per repository on the system.

The YUM GPG keyring (number 2 above) is the keyring that the information on this page refers to.

Import GPG key for seccubus/latest

To import a GPG key to verify YUM metadata, you must create a repo config with the GPG key URL. This is done automatically with all of our install methods.

If you'd like to do this manually for seccubus/latest, follow the instructions on the manual install page

Remove GPG key for seccubus/latest

Unfortunately GPG key removal is not particularly user friendly.

  1. Check your /etc/yum.conf file and note the value of persistdir. If persistdir is not set, you can assume it is /var/lib/yum.
  2. Determine which CPU architecture the repo has been installed for: i386 for 32-bit systems and x86_64 for 64-bit systems.
  3. Determine the verison number of the CentOS or Red Hat you are running (5, 6, or 7).
  4. Replace x86_64 and 7 in the following command with your CPU architecture and CentOS or RedHat version:
  5. gpg --homedir /var/lib/yum/repos/x86_64/7/seccubus_latest/gpgdir --delete-key A4DB23E1A7E9B462

APT GPG keys

NOTE: If you installed seccubus/latest with our Bash script, Chef cookbook, or Puppet module the GPG key is automatically installed. There is nothing additional you need to do.

GPG signature info

seccubus/latest has its APT metadata signed with seccubus-latest-A4DB23E1A7E9B462.pub.gpg.

Import GPG key for seccubus/latest

  1. Ensure you have curl installed:
    sudo apt-get install curl
  2. Ensure you have GPG installed:
    sudo apt-get install gnupg
  3. Add the GPG key:
    curl -L https://packagecloud.io/seccubus/latest/gpgkey | sudo apt-key add -

Remove GPG key for seccubus/latest

  1. Remove the GPG key:
    sudo apt-key remove A4DB23E1A7E9B462
  2. You will see the output "OK" when complete. You can verify the key has been removed by running:
    sudo apt-key list

List all GPG keys known to APT

  1. List all GPG keys known to APT:
    apt-key list

Package signing keys

GPG key name Key ID Delete
seccubus-latest-8BBD522354698C87.pub.gpg 8BBD522354698C87 delete
seccubus-latest-E78B0C0A17CC2953.pub.gpg E78B0C0A17CC2953 delete
close
Created with Sketch.

Drop a package to begin uploading…