NO_PUBKEY 🐧 Linux

The following signatures couldn't be verified because the public key is not available: NO_PUBKEY

apt can’t verify a repository’s signature because the repo’s signing key isn’t installed (or has expired/rotated).

Seen on: Linux

Meaning

Third-party repos (Docker, Node, Google Chrome, PostgreSQL) sign their indexes. Their key must be in /etc/apt/keyrings and referenced with signed-by in the source entry. apt-key is deprecated, and old keys get rotated.

Common causes

  • Repo added without importing its key
  • Key rotated by the vendor
  • Using deprecated apt-key with a keyring apt doesn’t read
  • signed-by path wrong

⚡ Quick fix

  1. Download the vendor’s current key into /etc/apt/keyrings
  2. Reference it with signed-by in the .list/.sources file
  3. Remove the repo if you no longer need it

Detailed fix by platform

Ubuntu

  1. bash
    sudo install -m 0755 -d /etc/apt/keyrings
    curl -fsSL https://download.docker.com/linux/ubuntu/gpg | sudo gpg --dearmor -o /etc/apt/keyrings/docker.gpg
    echo "deb [signed-by=/etc/apt/keyrings/docker.gpg] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable" | sudo tee /etc/apt/sources.list.d/docker.list
    sudo apt update

How to diagnose

  1. Repo — Which source fails?
  2. Key — Present in /etc/apt/keyrings and signed-by correct?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.