Skip to content
Snippets Groups Projects
update-keys 2.45 KiB
Newer Older
  • Learn to ignore specific revisions
  • #!/bin/bash
    
    
    TMPDIR=$(mktemp -d)
    trap "rm -rf '${TMPDIR}'" EXIT
    
    
    KEYSERVER='hkp://pool.sks-keyservers.net'
    
    GPG="gpg --quiet --batch --no-tty --no-permission-warning --export-options no-export-attributes --keyserver "${KEYSERVER}" --homedir ${TMPDIR}"
    
    
    pushd "$(dirname "$0")" >/dev/null
    
    
    $GPG --gen-key <<EOF
    %echo Generating Arch Linux Keyring keychain master key...
    Key-Type: RSA
    
    Key-Length: 1024
    
    Key-Usage: sign
    Name-Real: Arch Linux Keyring Keychain Master Key
    Name-Email: archlinux-keyring@localhost
    Expire-Date: 0
    
    Pierre Schmitz's avatar
    Pierre Schmitz committed
    %no-protection
    
    Bartłomiej Piotrowski's avatar
    Bartłomiej Piotrowski committed
    rm -rf master{,-revoked} packager{,-revoked} archlinux-{trusted,revoked}
    mkdir master packager master-revoked packager-revoked
    
    
    while read -ra data; do
    	keyid="${data[0]}"
    	username="${data[@]:1}"
    	${GPG} --recv-keys ${keyid} &>/dev/null
    
    	printf 'minimize\nquit\ny\n' | \
    		${GPG} --command-fd 0 --edit-key ${keyid}
    
    	${GPG} --yes --lsign-key ${keyid} &>/dev/null
    
    	${GPG} --armor --no-emit-version --export ${keyid} >> master/${username}.asc
    
    	echo "${keyid}:4:" >> archlinux-trusted
    
    done < master-keyids
    
    ${GPG} --import-ownertrust < archlinux-trusted 2>/dev/null
    
    Bartłomiej Piotrowski's avatar
    Bartłomiej Piotrowski committed
    while read -ra data; do
    	keyid="${data[0]}"
    	username="${data[1]}"
    	${GPG} --recv-keys ${keyid} &>/dev/null
    	printf 'clean\nquit\ny\n' | \
    		${GPG} --command-fd 0 --edit-key ${keyid}
    
    	${GPG} --armor --no-emit-version --export-options export-minimal --export ${keyid} >> master-revoked/${username}.asc
    	echo "${keyid}" >> archlinux-revoked
    
    Bartłomiej Piotrowski's avatar
    Bartłomiej Piotrowski committed
    done < master-revoked-keyids
    
    
    while read -ra data; do
    	keyid="${data[0]}"
    	${GPG} --recv-keys ${keyid} &>/dev/null
    
    done < packager-keyids
    while read -ra data; do
    	keyid="${data[0]}"
    	username="${data[@]:1}"
    
    	printf 'clean\nquit\ny\n' | \
    		${GPG} --command-fd 0 --edit-key ${keyid}
    
    	if ! ${GPG} --list-keys --with-colons ${keyid} 2>/dev/null | grep -q '^pub:f:'; then
    		echo "key is not fully trusted: ${keyid} ${username}"
    	else
    
    		${GPG} --armor --no-emit-version --export ${keyid} >> packager/${username}.asc
    
    	fi
    done < packager-keyids
    
    
    while read -ra data; do
    	keyid="${data[0]}"
    	username="${data[1]}"
    	${GPG} --recv-keys ${keyid} &>/dev/null
    	printf 'clean\nquit\ny\n' | \
    		${GPG} --command-fd 0 --edit-key ${keyid}
    
    	${GPG} --armor --no-emit-version --export-options export-minimal --export ${keyid} >> packager-revoked/${username}.asc
    	echo "${keyid}" >> archlinux-revoked
    
    done < packager-revoked-keyids
    
    
    Bartłomiej Piotrowski's avatar
    Bartłomiej Piotrowski committed
    cat master/*.asc master-revoked/*.asc packager/*.asc packager-revoked/*.asc > archlinux.gpg
    
    popd >/dev/null