-
-
Notifications
You must be signed in to change notification settings - Fork 2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
update installation instructions with new repo #9500
Conversation
change mentions of https://riot.im/packages to https://packages.riot.im add instructions to remove old, now-untrusted riot.im signing key update language and move from 'apt-get` to the simpler `apt`
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
otherwise looks great, thanks!
better wording Co-Authored-By: axelsimon <github@axelsimon.net>
README.md
Outdated
Releases are signed by PGP, and can be checked against the public key | ||
at https://riot.im/packages/keys/riot.asc . | ||
Releases are signed using gpg and the OpenPGP standard, and can be checked against the public key located | ||
at https://packages.riot.im/debian/riot.im-archive-keyring.asc . |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This doesn't exist, did you mean riot-im-archive-keyring.asc
? Also someone is going to have to explain to me the difference between that and https://packages.riot.im/riot-release-key.asc
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Good catch. Thanks.
I really meant https://packages.riot.im/riot-release-key.asc, I'll amend.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
given that's also Dave's suggestion, I'm inclined to trust that too :D
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
So we've got https://packages.riot.im/riot-release-key.asc for the general package signing and https://packages.riot.im/debian/riot.im-archive-keyring.asc as the key to add to apt's key store, on Debian. Correct?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Those sound like the right things to me
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yep, that's right - the signing keys are now separate with one the one in /debian for the debian repo and the release key for signing the web release tarballs.
apt-get
to the simplerapt
Signed-off-by: axel simon
<axelsimon at axelsimon.net>