You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker容器APT更新遇NO_PUBKEY问题,无法安装gnupg

Docker容器APT更新GPG密钥错误解决

问题场景

在Docker容器中执行apt update时遭遇GPG证书验证失败,提示NO_PUBKEY 871920D1991BC93C;尝试通过apt-key命令导入公钥,但容器未安装gnupg工具;尝试安装gnupg时,又因仓库签名问题无法找到安装候选,容器已配置代理。

命令执行日志

apt update
Get:1 http://security.ubuntu.com/ubuntu jammy-security InRelease [110 kB]
Get:2 http://archive.ubuntu.com/ubuntu jammy InRelease [270 kB]
Err:1 http://security.ubuntu.com/ubuntu jammy-security InRelease
  The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 871920D1991BC93C
Get:3 http://archive.ubuntu.com/ubuntu jammy-updates InRelease [114 kB]
Err:2 http://archive.ubuntu.com/ubuntu jammy InRelease
  The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 871920D1991BC93C
Err:3 http://archive.ubuntu.com/ubuntu jammy-updates InRelease
  The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 871920D1991BC93C
Get:4 http://archive.ubuntu.com/ubuntu jammy-backports InRelease [99.8 kB]
Err:4 http://archive.ubuntu.com/ubuntu jammy-backports InRelease
  The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 871920D1991BC93C
Reading package lists... Done
W: http://security.ubuntu.com/ubuntu/dists/jammy-security/InRelease: The key(s) in the keyring /etc/apt/trusted.gpg.d/ubuntu-keyring-2012-cdimage.gpg are ignored as the file is not readable by user '_apt' executing apt-key.
W: http://security.ubuntu.com/ubuntu/dists/jammy-security/InRelease: The key(s) in the keyring /etc/apt/trusted.gpg.d/ubuntu-keyring-2018-archive.gpg are ignored as the file is not readable by user '_apt' executing apt-key.
W: GPG error: http://security.ubuntu.com/ubuntu jammy-security InRelease: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 871920D1991BC93C
E: The repository 'http://security.ubuntu.com/ubuntu jammy-security InRelease' is not signed.
N: Updating from such a repository can't be done securely, and is therefore disabled by default.
N: See apt-secure(8) manpage for repository creation and user configuration details.
W: http://archive.ubuntu.com/ubuntu/dists/jammy/InRelease: The key(s) in the keyring /etc/apt/trusted.gpg.d/ubuntu-keyring-2012-cdimage.gpg are ignored as the file is not readable by user '_apt' executing apt-key.
W: http://archive.ubuntu.com/ubuntu/dists/jammy/InRelease: The key(s) in the keyring /etc/apt/trusted.gpg.d/ubuntu-keyring-2018-archive.gpg are ignored as the file is not readable by user '_apt' executing apt-key.
W: GPG error: http://archive.ubuntu.com/ubuntu jammy InRelease: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 871920D1991BC93C
E: The repository 'http://archive.ubuntu.com/ubuntu jammy InRelease' is not signed.
N: Updating from such a repository can't be done securely, and is therefore disabled by default.
N: See apt-secure(8) manpage for repository creation and user configuration details.
W: http://archive.ubuntu.com/ubuntu/dists/jammy-updates/InRelease: The key(s) in the keyring /etc/apt/trusted.gpg.d/ubuntu-keyring-2012-cdimage.gpg are ignored as the file is not readable by user '_apt' executing apt-key.
W: http://archive.ubuntu.com/ubuntu/dists/jammy-updates/InRelease: The key(s) in the keyring /etc/apt/trusted.gpg.d/ubuntu-keyring-2018-archive.gpg are ignored as the file is not readable by user '_apt' executing apt-key.
W: GPG error: http://archive.ubuntu.com/ubuntu jammy-updates InRelease: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 871920D1991BC93C
E: The repository 'http://archive.ubuntu.com/ubuntu jammy-updates InRelease' is not signed.
N: Updating from such a repository can't be done securely, and is therefore disabled by default.
N: See apt-secure(8) manpage for repository creation and user configuration details.
W: http://archive.ubuntu.com/ubuntu/dists/jammy-backports/InRelease: The key(s) in the keyring /etc/apt/trusted.gpg.d/ubuntu-keyring-2012-cdimage.gpg are ignored as the file is not readable by user '_apt' executing apt-key.
W: http://archive.ubuntu.com/ubuntu/dists/jammy-backports/InRelease: The key(s) in the keyring 
/etc/apt/trusted.gpg.d/ubuntu-keyring-2018-archive.gpg are ignored as the file is not readable by user '_apt' executing apt-key.
W: GPG error: http://archive.ubuntu.com/ubuntu jammy-backports InRelease: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 871920D1991BC93C
E: The repository 'http://archive.ubuntu.com/ubuntu jammy-backports InRelease' is not signed.
N: Updating from such a repository can't be done securely, and is therefore disabled by default.
N: See apt-secure(8) manpage for repository creation and user configuration details.
E: Problem executing scripts APT::Update::Post-Invoke 'rm -f /var/cache/apt/archives/*.deb /var/cache/apt/archives/partial/*.deb /var/cache/apt/*.bin || true'
E: Sub-process returned an error code

root@f63068899287:/# apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 871920D1991BC93C
E: gnupg, gnupg2 and gnupg1 do not seem to be installed, but one of them is required for this operation
root@f63068899287:/#

root@f63068899287:/# apt install gnupg
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
Package gnupg is not available, but is referred to by another package.
This may mean that the package is missing, has been obsoleted, or
is only available from another source

E: Package 'gnupg' has no installation candidate

解决方案

方法1:手动下载并添加公钥(推荐)

利用容器已配置的代理,直接通过curl/wget下载公钥并添加到apt信任列表,同时修正文件权限:

  1. 检查容器是否有curl或wget:
    which curl || which wget
    
  2. 若有curl,执行以下命令下载公钥:
    curl -sSL "http://keyserver.ubuntu.com/pks/lookup?op=get&search=0x871920D1991BC93C" | tee /etc/apt/trusted.gpg.d/ubuntu-jammy-key.gpg
    
  3. 若只有wget,执行:
    wget -O- "http://keyserver.ubuntu.com/pks/lookup?op=get&search=0x871920D1991BC93C" | tee /etc/apt/trusted.gpg.d/ubuntu-jammy-key.gpg
    
  4. 修改公钥文件权限,确保_apt用户可读取:
    chmod 644 /etc/apt/trusted.gpg.d/ubuntu-jammy-key.gpg
    
  5. 再次执行更新并安装gnupg:
    apt update && apt install -y gnupg
    

方法2:临时跳过仓库签名验证(应急用)

通过修改APT配置临时允许未签名仓库,先安装gnupg再修复密钥问题:

  1. 创建临时APT配置文件:
    echo "Acquire::AllowInsecureRepositories true;" > /etc/apt/apt.conf.d/99insecure
    echo "Acquire::AllowDowngradeToInsecureRepositories true;" >> /etc/apt/apt.conf.d/99insecure
    
  2. 安装gnupg:
    apt update && apt install -y gnupg
    
  3. 导入缺失的公钥:
    apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 871920D1991BC93C
    
  4. 删除临时配置文件,恢复安全验证:
    rm /etc/apt/apt.conf.d/99insecure
    
  5. 重新执行正常更新:
    apt update
    

方法3:从宿主机复制gnupg文件(复杂场景)

如果容器内没有curl/wget且无法安装,可从同版本Ubuntu宿主机复制gnupg二进制文件及依赖到容器,步骤如下:

  1. 在宿主机找到gnupg相关路径:
    which gnupg
    
  2. 复制文件到容器(假设容器ID为f63068899287):
    docker cp /usr/bin/gnupg f63068899287:/usr/bin/
    docker cp /usr/lib/x86_64-linux-gnu/libgpg-error.so.0 f63068899287:/usr/lib/x86_64-linux-gnu/
    # 按需复制其他依赖库,可通过ldd /usr/bin/gnupg查看所有依赖
    
  3. 回到容器执行导入公钥命令,后续步骤同方法1。

内容的提问来源于stack exchange,提问作者codewithniraj

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.18 23:05:24