← Back to issue list

snap does not support revocation of signing keys

View original Launchpad issue

Metadata

Project
snapcraft (launchpad)
Number
#1744013
Type
issue
State
open
Author
~vilvo
Labels
Created
Updated
Closed

Current evaluation

Reports that snapcraft's model assertion signing process (snap sign) provides no way to revoke signing keys. 8.6 years old with zero comments, no labels, and no maintainer interaction; unverified whether the store now supports key revocation.

Suggested action: needs triage

Reason: The issue has no labels, zero comments, and no maintainer acknowledgement in 3147 days, showing no sign of ever being triaged. However, close_stale is not justified because I could not verify (code inspection tools returned 'No pinned SHA available' errors) that key revocation was implemented elsewhere, and the snap sign model-assertion workflow still exists, so the gap may still be open. A maintainer should confirm whether the store now supports key revocation before deciding.

Impact: 30 Quick Win: 13.5 Staleness: 95 Complexity: 55 Confidence: 55 Support Request: 30

Issue body

snapcraft signing model assertion process does not support revocation of the signing keys. How to reproduce: 1) Login snapcraft > snapcraft login 2) Create default key (need to be done only once) > snapcraft create-key 3) Generate timestamp > date -Iseconds --utc 4) Copy the result of date into the timestamp field of the model file e.g. board-model.json 5) Log into your account and copy "Snap account-id" into both the "authority-id" and the "brand-id" fields in the file board-model.json: https://dashboard.snapcraft.io/dev/account/ 6) Create a new model assertion by running: > cat board-model.json | snap sign -k default &> board.model 7) There is no way to revoke the created key.

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.8-27b
Impact: 30
Quick Win: 13.5
Staleness: 95
Complexity: 55
Confidence: 55
Support Request: 30
needs triage Reports that snapcraft's model assertion signing process (snap sign) provides no way to revoke signing keys. 8.6 years old with zero comments, no labels, and no maintainer interaction; unverified whether the store now supports key revocation.
qwen/qwen3.6-35b-a3b
Staleness: 98
Complexity: 65
Confidence: 85
Support Request: 20
close stale Feature request stating snapcraft lacks signing key revocation. Open for over 8 years with no maintainer response. The described workflow and missing functionality are irrelevant to current project versions.
qwen/qwen3.6-35b-a3b
Staleness: 98
Complexity: 75
Confidence: 70
Support Request: 10
close stale Reports inability to revoke snapcraft signing keys used for model assertions. Unlabeled, no maintainer interaction, and inactive for over 8 years.
qwen3.6-35b-a3b-mtp-q6
Staleness: 95
Complexity: 75
Confidence: 85
Support Request: 10
needs triage Snapcraft lacks a mechanism to revoke signing keys used for model assertions. Open for over 8 years with no maintainer response or comments.
qwen3.6-35b-moe-q4
Staleness: 98
Complexity: 75
Confidence: 90
Support Request: 20
close stale Reports missing key revocation in snapcraft signing workflow. No maintainer response, labels, or activity in over 8 years.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#1669471 problems on revoking a gpg key for signing assertions snapcraft (launchpad) open snapcraft revoke-key prints usage help instead of revoking a GPG key (snapcraft 2.27.1). No comments or maintainer response for ~9.5 years. Version is long deprecated and store commands were reorganized under the snapcraft store subcommand.
78%
#1800825 Missing account-key revocation support snapcraft (launchpad) open Feature request for account-key revocation in snapcraft (destructive or timeproof-based selective), plus better CLI guidance on key backup/restore. Open ~7.8 years with zero comments and no maintainer interaction; interim suggestion likely outdated.
71%