Docker容器APT更新遇NO_PUBKEY问题,无法安装gnupg
Docker容器APT更新GPG密钥错误解决
问题场景
在Docker容器中执行apt update时遭遇GPG证书验证失败,提示NO_PUBKEY 871920D1991BC93C;尝试通过apt-key命令导入公钥,但容器未安装gnupg工具;尝试安装gnupg时,又因仓库签名问题无法找到安装候选,容器已配置代理。
命令执行日志
apt update Get:1 http://security.ubuntu.com/ubuntu jammy-security InRelease [110 kB] Get:2 http://archive.ubuntu.com/ubuntu jammy InRelease [270 kB] Err:1 http://security.ubuntu.com/ubuntu jammy-security InRelease The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 871920D1991BC93C Get:3 http://archive.ubuntu.com/ubuntu jammy-updates InRelease [114 kB] Err:2 http://archive.ubuntu.com/ubuntu jammy InRelease The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 871920D1991BC93C Err:3 http://archive.ubuntu.com/ubuntu jammy-updates InRelease The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 871920D1991BC93C Get:4 http://archive.ubuntu.com/ubuntu jammy-backports InRelease [99.8 kB] Err:4 http://archive.ubuntu.com/ubuntu jammy-backports InRelease The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 871920D1991BC93C Reading package lists... Done W: http://security.ubuntu.com/ubuntu/dists/jammy-security/InRelease: The key(s) in the keyring /etc/apt/trusted.gpg.d/ubuntu-keyring-2012-cdimage.gpg are ignored as the file is not readable by user '_apt' executing apt-key. W: http://security.ubuntu.com/ubuntu/dists/jammy-security/InRelease: The key(s) in the keyring /etc/apt/trusted.gpg.d/ubuntu-keyring-2018-archive.gpg are ignored as the file is not readable by user '_apt' executing apt-key. W: GPG error: http://security.ubuntu.com/ubuntu jammy-security InRelease: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 871920D1991BC93C E: The repository 'http://security.ubuntu.com/ubuntu jammy-security InRelease' is not signed. N: Updating from such a repository can't be done securely, and is therefore disabled by default. N: See apt-secure(8) manpage for repository creation and user configuration details. W: http://archive.ubuntu.com/ubuntu/dists/jammy/InRelease: The key(s) in the keyring /etc/apt/trusted.gpg.d/ubuntu-keyring-2012-cdimage.gpg are ignored as the file is not readable by user '_apt' executing apt-key. W: http://archive.ubuntu.com/ubuntu/dists/jammy/InRelease: The key(s) in the keyring /etc/apt/trusted.gpg.d/ubuntu-keyring-2018-archive.gpg are ignored as the file is not readable by user '_apt' executing apt-key. W: GPG error: http://archive.ubuntu.com/ubuntu jammy InRelease: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 871920D1991BC93C E: The repository 'http://archive.ubuntu.com/ubuntu jammy InRelease' is not signed. N: Updating from such a repository can't be done securely, and is therefore disabled by default. N: See apt-secure(8) manpage for repository creation and user configuration details. W: http://archive.ubuntu.com/ubuntu/dists/jammy-updates/InRelease: The key(s) in the keyring /etc/apt/trusted.gpg.d/ubuntu-keyring-2012-cdimage.gpg are ignored as the file is not readable by user '_apt' executing apt-key. W: http://archive.ubuntu.com/ubuntu/dists/jammy-updates/InRelease: The key(s) in the keyring /etc/apt/trusted.gpg.d/ubuntu-keyring-2018-archive.gpg are ignored as the file is not readable by user '_apt' executing apt-key. W: GPG error: http://archive.ubuntu.com/ubuntu jammy-updates InRelease: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 871920D1991BC93C E: The repository 'http://archive.ubuntu.com/ubuntu jammy-updates InRelease' is not signed. N: Updating from such a repository can't be done securely, and is therefore disabled by default. N: See apt-secure(8) manpage for repository creation and user configuration details. W: http://archive.ubuntu.com/ubuntu/dists/jammy-backports/InRelease: The key(s) in the keyring /etc/apt/trusted.gpg.d/ubuntu-keyring-2012-cdimage.gpg are ignored as the file is not readable by user '_apt' executing apt-key. W: http://archive.ubuntu.com/ubuntu/dists/jammy-backports/InRelease: The key(s) in the keyring /etc/apt/trusted.gpg.d/ubuntu-keyring-2018-archive.gpg are ignored as the file is not readable by user '_apt' executing apt-key. W: GPG error: http://archive.ubuntu.com/ubuntu jammy-backports InRelease: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 871920D1991BC93C E: The repository 'http://archive.ubuntu.com/ubuntu jammy-backports InRelease' is not signed. N: Updating from such a repository can't be done securely, and is therefore disabled by default. N: See apt-secure(8) manpage for repository creation and user configuration details. E: Problem executing scripts APT::Update::Post-Invoke 'rm -f /var/cache/apt/archives/*.deb /var/cache/apt/archives/partial/*.deb /var/cache/apt/*.bin || true' E: Sub-process returned an error code root@f63068899287:/# apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 871920D1991BC93C E: gnupg, gnupg2 and gnupg1 do not seem to be installed, but one of them is required for this operation root@f63068899287:/# root@f63068899287:/# apt install gnupg Reading package lists... Done Building dependency tree... Done Reading state information... Done Package gnupg is not available, but is referred to by another package. This may mean that the package is missing, has been obsoleted, or is only available from another source E: Package 'gnupg' has no installation candidate
解决方案
方法1:手动下载并添加公钥(推荐)
利用容器已配置的代理,直接通过curl/wget下载公钥并添加到apt信任列表,同时修正文件权限:
- 检查容器是否有curl或wget:
which curl || which wget - 若有curl,执行以下命令下载公钥:
curl -sSL "http://keyserver.ubuntu.com/pks/lookup?op=get&search=0x871920D1991BC93C" | tee /etc/apt/trusted.gpg.d/ubuntu-jammy-key.gpg - 若只有wget,执行:
wget -O- "http://keyserver.ubuntu.com/pks/lookup?op=get&search=0x871920D1991BC93C" | tee /etc/apt/trusted.gpg.d/ubuntu-jammy-key.gpg - 修改公钥文件权限,确保
_apt用户可读取:chmod 644 /etc/apt/trusted.gpg.d/ubuntu-jammy-key.gpg - 再次执行更新并安装gnupg:
apt update && apt install -y gnupg
方法2:临时跳过仓库签名验证(应急用)
通过修改APT配置临时允许未签名仓库,先安装gnupg再修复密钥问题:
- 创建临时APT配置文件:
echo "Acquire::AllowInsecureRepositories true;" > /etc/apt/apt.conf.d/99insecure echo "Acquire::AllowDowngradeToInsecureRepositories true;" >> /etc/apt/apt.conf.d/99insecure - 安装gnupg:
apt update && apt install -y gnupg - 导入缺失的公钥:
apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 871920D1991BC93C - 删除临时配置文件,恢复安全验证:
rm /etc/apt/apt.conf.d/99insecure - 重新执行正常更新:
apt update
方法3:从宿主机复制gnupg文件(复杂场景)
如果容器内没有curl/wget且无法安装,可从同版本Ubuntu宿主机复制gnupg二进制文件及依赖到容器,步骤如下:
- 在宿主机找到gnupg相关路径:
which gnupg - 复制文件到容器(假设容器ID为
f63068899287):docker cp /usr/bin/gnupg f63068899287:/usr/bin/ docker cp /usr/lib/x86_64-linux-gnu/libgpg-error.so.0 f63068899287:/usr/lib/x86_64-linux-gnu/ # 按需复制其他依赖库,可通过ldd /usr/bin/gnupg查看所有依赖 - 回到容器执行导入公钥命令,后续步骤同方法1。
内容的提问来源于stack exchange,提问作者codewithniraj
相关产品推荐
相关产品推荐

