diff --git a/changelog.d/20066.doc b/changelog.d/20066.doc new file mode 100644 index 0000000000..0ac03b9fa9 --- /dev/null +++ b/changelog.d/20066.doc @@ -0,0 +1 @@ +Add upgrade notes to point out updated Debian package signing key. diff --git a/docs/upgrade.md b/docs/upgrade.md index 2f65d86cbe..a3c529f1f1 100644 --- a/docs/upgrade.md +++ b/docs/upgrade.md @@ -117,6 +117,27 @@ each upgrade are complete before moving on to the next upgrade, to avoid stacking them up. You can monitor the currently running background updates with [the Admin API](usage/administration/admin_api/background_updates.html#status). + +# Upgrading to v1.159.0 + +## Change of signing key expiry date for the Debian/Ubuntu package repository (2026) + +Administrators using the Debian/Ubuntu packages from `packages.matrix.org`, +please be aware that we have recently updated the expiry date on the repository's GPG signing key, +but this change must be imported into your keyring. + +If you have the `matrix-org-archive-keyring` package installed and it updates before the current key expires, this should +happen automatically. + +Otherwise, if you see an error similar to `The following signatures were invalid: EXPKEYSIG F473DD4473365DE1`, you +will need to get a fresh copy of the keys. You can do so with: + +```sh +sudo wget -O /usr/share/keyrings/matrix-org-archive-keyring.gpg https://packages.matrix.org/debian/matrix-org-archive-keyring.gpg +``` + +The old version of the key will expire on `2027-03-15`. + # Upgrading to v1.158.0 ## Drop support for Ubuntu 25.10 'Questing Quokka', add support for Ubuntu 26.04 'Resolute Raccoon'