Hello,
Hugo Buddelmeijer via "Development of GNU Guix and the GNU System
distribution." <[email protected]> skribis:
> Attempt 1, there is no keyserver defined:
In this case it’s using the default key server that happens to be
configured for GnuPG, in your local config file or in GnuPG itself.
> The manual is not particularly helpful here, because the command-line
> argument is `--key-server` instead of `--keyserver`, so I couldn't
> find it at first.
You can run ‘guix refresh --help’ or rely on tab completion, though.
Also, if one types “--keyserver”, the command prints:
guix refresh: error: keyserver: unrecognized option
hint: Did you mean `key-server'?
> Attempt 2:
>
> $ ./pre-inst-env guix refresh -u poppler
> --key-server=hkp://keyserver.ubuntu.com:80
>
> Starting download of /tmp/guix-file.YWyfHq
> From https://poppler.freedesktop.org/poppler-26.08.0.tar.xz...
> Starting download of /tmp/guix-file.5PSDYR
> From https://poppler.freedesktop.org/poppler-26.08.0.tar.xz.sig...
> gpgv: Signature made Sun 02 Aug 2026 11:32:46 PM CEST
> gpgv: using RSA key CA262C6C83DE4D2FB28A332A3A6A4DB839EAA6D7
> gpgv: Can't check signature: No public key
> Would you like to add this key to keyring
> '/home/hugo/.config/guix/upstream/trustedkeys.kbx'?
> yes
> gpg: Note: Specified keyrings are ignored due to option "use-keyboxd"
> gpg: NOTE: THIS IS A DEVELOPMENT VERSION!
> gpg: It is only intended for test purposes and should NOT be
> gpg: used in a production environment or with production keys!
> gpg: key 3A6A4DB839EAA6D7: public key "Albert Astals Cid
> <[email protected]>" imported
> gpg: Total number processed: 1
> gpg: imported: 1
> gpgv: Signature made Sun 02 Aug 2026 11:32:46 PM CEST
> gpgv: using RSA key CA262C6C83DE4D2FB28A332A3A6A4DB839EAA6D7
> gpgv: Can't check signature: No public key
> guix refresh: warning: signature verification failed for
> 'https://poppler.freedesktop.org/poppler-26.08.0.tar.xz' (key:
> CA262C6C83DE4D2FB28A332A3A6A4DB839EAA6D7)
> guix refresh: warning: poppler: version 26.08.0 could not be
> downloaded and authenticated; not updating
Weird because the key was apparently imported. Could you check this:
gpg --no-default-keyring \
--keyring ~/.config/guix/upstream/trustedkeys.kbx --list-keys
Does it show the key that that was imported above?
I tried this locally:
./pre-inst-env guix refresh --key-server=keyserver.ubuntu.com -u poppler
It successfully downloaded the key and then successfully authenticated
the tarball.
At any rate, we should improve diagnostics for the situation above with
something like:
diff --git a/guix/gnupg.scm b/guix/gnupg.scm
index 498f8b34a92..a71cc3cda40 100644
--- a/guix/gnupg.scm
+++ b/guix/gnupg.scm
@@ -253,7 +253,15 @@ (define* (gnupg-verify* sig file
((fingerprint . user)
(values 'valid-signature
(cons fingerprint user))))
- (values 'missing-key missing)))
+ (begin
+ (if server
+ (warning (G_ "failed to download OpenPGP key '~a' \
+from '~a'~%")
+ missing server)
+ (warning (G_ "failed to download OpenPGP key '~a' \
+from default key server~%")
+ missing))
+ (values 'missing-key missing))))
(define (receive?)
(let ((answer
Thanks,
Ludo’.