# Nexus Repository Manager OSS via APT | NO\_PUBKEY

**URL:** https://community.sonatype.com/t/nexus-repository-manager-oss-via-apt-no-pubkey/13084
**Category:** Sonatype Nexus Repository
**Created:** [August 19, 2024, 3:02pm UTC](https://community.sonatype.com/t/nexus-repository-manager-oss-via-apt-no-pubkey/13084 "2024-08-19T15:02:26Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![zyzonix](https://avatars.discourse-cdn.com/v4/letter/z/ecccb3/32.png) [@zyzonix](https://community.sonatype.com/u/zyzonix)
#### Post date: [August 19, 2024, 3:02pm UTC](https://community.sonatype.com/t/nexus-repository-manager-oss-via-apt-no-pubkey/13084/1 "2024-08-19T15:02:27Z")

</div>

Hello,

we’re using the Nexus Repository Manager for hosting our own Chocolatey packages. Everything works fine, but yesterday I discovered, that the update via APT from [Sonatype Nexus Repository](https://repo.sonatype.com/#browse/browse:community-apt-hosted) fails.  
The error message APT prints is the following:

```auto
Get:4 https://repo.sonatype.com/repository/community-apt-hosted bionic InRelease [1,387 B]
Err:4 https://repo.sonatype.com/repository/community-apt-hosted bionic InRelease
  The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 964B5E720AA4F31A
Reading package lists... Done
W: GPG error: https://repo.sonatype.com/repository/community-apt-hosted bionic InRelease: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY 964B5E720AA4F31A
E: The repository 'https://repo.sonatype.com/repository/community-apt-hosted bionic InRelease' is not signed.
N: Updating from such a repository can't be done securely, and is therefore disabled by default.
N: See apt-secure(8) manpage for repository creation and user configuration details.

```

I installed the key via:

```auto
wget -q -O - https://repo.sonatype.com/repository/community-hosted/pki/deb-gpg/DEB-GPG-KEY-Sonatype.asc | sudo apt-key add -

```

What can I do now?  
_Edit:_  
And when using

```auto
sudo apt-key adv --keyserver keyserver.ubuntu.com --recv-keys 964B5E720AA4F31A

```

I only get a key that already expired…

_Edit 2:_  
It seems that the Release-File is signed with a different key that the key provided.  
ID of key used to sign: `964B5E720AA4F31A`  
ID of provided key: `7DC565E26783520F`

–  
Best regards
