On Sun, 1 Jan 2017 16:31:27 +0300 Andrew Savchenko <[email protected]> wrote:
> Hi, > > On Sun, 1 Jan 2017 18:12:23 +0700 (+07) [email protected] wrote: > > Happy new year to *, > > > > Yesterday I've changed expiration dates of my gpg key and its > > subkeys. And today I cannot push to Gentoo repo: > > > > remote: Signature found, but from unknown key (see push-cert) > > remote: Your push was not signed with a known key. > > remote: You MUST use git push --signed with a known key. > > remote: If you just updated your key, please wait 15 minutes for > > sync. remote: git-receive-pack variables: > > remote: GIT_PUSH_CERT='ef16430106a13fa3758d2211100be5b9f2bd88d8' > > remote: GIT_PUSH_CERT_KEY='' > > remote: GIT_PUSH_CERT_NONCE='1483268914-e0cd9c07e06304c00a64' > > remote: GIT_PUSH_CERT_NONCE_SLOP='' > > remote: GIT_PUSH_CERT_NONCE_STATUS='OK' > > remote: GIT_PUSH_CERT_SIGNER='' > > remote: GIT_PUSH_CERT_STATUS='N' > > remote: A push-cert was found, and follows: > > remote: ===== > > remote: certificate version 0.1 > > remote: pusher 0x3AFFCE974D34BD8C 1483268914 +0700 > > Looks like git hook is still using your old key. You should wait > for a day or so in order for your change to propagate through > servers. It this doesn't help, you should probably contact infra to > update your key. > > Best regards, > Andrew Savchenko No, infra has it refreshing keys several times an hour. I just dig another gkeys run and refreshed the keys from the servers. You did not reset the expiry on your signing subkey. See the following reports which show the details. After you reset it and gpg --send-key it to the keyservers again. It can take a few hours for it to propagate and to be able to push to the gentoo repo again. =================================================== dolsen@vulture /var/lib/gkeys $ python3.4 /var/lib/gkeys/gentoo-keys/gkeys/bin/gkeys -c /var/lib/gkeys/gkeys.conf list-key -C gentoo-devs -n grozin Nick.....: grozin Name.....: Andrey Grozin Keydir...: grozin Gpg info.: /var/lib/gkeys/keyrings/gentoo-devs/grozin/pubring.gpg ------------------------------------------------------ pub rsa4096/53D4ABFA88DD61C4 2013-02-26 [SC] [expires: 2017-12-24] Key fingerprint = 6FCC 83E2 6D94 FB05 4B76 1016 53D4 ABFA 88DD 61C4 uid [ unknown] Andrey Grozin (science) <[email protected]> sub rsa4096/34966948B00C83E6 2013-02-26 [E] [expires: 2017-12-24] Gkey task results: Done. dolsen@vulture /var/lib/gkeys $ python3.4 /var/lib/gkeys/gentoo-keys/gkeys/bin/gkeys -c /var/lib/gkeys/gkeys.conf spec-check -C gentoo-devs -n grozin Checking keys... grozin, Andrey Grozin: 0x53D4ABFA88DD61C4 ============================================== ---------- Fingerprint......: 6FCC83E26D94FB054B76101653D4ABFA88DD61C4 Key type ........: PUB Capabilities.: scESC Algorithm........: Pass Bit Length...: Pass Create Date......: Pass Expire Date..: Pass Key Version......: Pass Validity.....: -, Unknown Days till expiry.: 356 Capability.......: Pass Qualified ID.....: Pass This primary key.: Pass ---------- Fingerprint......: 902F154026C4AD5055486D0234966948B00C83E6 Key type ........: SUB Capabilities.: e encrypt Algorithm........: ---- Bit Length...: ---- Create Date......: Pass Expire Date..: Pass Key Version......: Pass Validity.....: -, Unknown Days till expiry.: 356 Capability.......: Pass Qualified ID.....: Pass This subkey......: Pass ---------- Fingerprint......: 08C4EDF669C5A630FE7DEB943AFFCE974D34BD8C Key type ........: SUB Capabilities.: s Algorithm........: Pass Bit Length...: Pass Create Date......: Pass Expire Date..: Pass Key Version......: Pass Validity.....: e, Expired Days till expiry.: 0 Capability.......: Pass Qualified ID.....: Pass This subkey......: Fail Key summary primary..........: Pass signing subkey: Fail encryption subkey: Yes authentication subkey: No SPEC requirements: Fail No signing capable subkey: Andrey Grozin <grozin>: 6FCC83E26D94FB054B76101653D4ABFA88DD61C4 Failed to pass SPEC requirements: Andrey Grozin <grozin>: 6FCC83E26D94FB054B76101653D4ABFA88DD61C4 Gkey task results: Found Failures: ------- Revoked................: 0 Invalid................: 0 No Signing subkey......: 1 No Encryption subkey...: 0 Algorithm..............: 0 Bit length.............: 0 Qualified IDs..........: 0 Expiry.................: 0 Expiry Warnings........: 0 SPEC requirements......: 1 ============================= SPEC Approved..........: 0 dolsen@vulture /var/lib/gkeys $ -- Brian Dolbec <dolsen>
pgpiNpf50PLG8.pgp
Description: OpenPGP digital signature
