← Browse

@cyberstrikeus/cis-ubuntu-14-04-lts-1-2-2-ensure-gpg-keys-are-configured

B

Verify that GPG keys are configured for package manager to ensure package integrity

skillclaude

Install

agr install @cyberstrikeus/cis-ubuntu-14-04-lts-1-2-2-ensure-gpg-keys-are-configured --target claude

Writes 1 file into .claude/skills/, pinned to git-22078e7d.

  • .claude/skills/cis-ubuntu-14-04-lts-1-2-2-ensure-gpg-keys-are-configured/SKILL.md

Document


name: "CIS Ubuntu 14.04 LTS - 1.2.2 Ensure GPG keys are configured" description: "Verify that GPG keys are configured for package manager to ensure package integrity" category: "cis-os-hardening" version: "2.1.0" author: "cyberstrike-official" tags:

  • cis
  • ubuntu
  • ubuntu-14.04
  • level-1
  • not-scored
  • software-updates cis_id: "1.2.2" cis_benchmark: "CIS Ubuntu Linux 14.04 LTS Benchmark v2.1.0" tech_stack:
  • ubuntu
  • linux cwe_ids: [] chains_with: [] prerequisites: [] severity_boost: "medium"

1.2.2 Ensure GPG keys are configured (Not Scored)

Profile Applicability

  • Level 1 - Server
  • Level 1 - Workstation

Description

Most packages managers implement GPG key signing to verify package integrity during installation.

Rationale

It is important to ensure that updates are obtained from a valid source to protect against spoofing that could lead to the inadvertent installation of malware on the system.

Audit Procedure

Run the following command and verify GPG keys are configured correctly for your package manager:

apt-key list

Expected Result

Verify that GPG keys are configured according to site policy.

Remediation

Update your package manager GPG keys in accordance with site policy.

Default Value

Not applicable. Configuration varies by site policy.

References

  • CIS Controls: 4.5 Use Automated Patch Management And Software Update Tools

Profile

  • Level 1 - Server
  • Level 1 - Workstation

Trustgrade B

  • passBody integrity

    Whether the stored document is plausibly the kind of file the artifact declares, rather than something fetched by mistake.

  • passType matchnot applicable to this artifact type

    Whether the artifact is really the kind of thing its metadata claims it is.

  • passFreshness

    How long since the source repository was last pushed to.

  • passPrompt injection

    Scans the artifact's own text for instructions aimed at your agent rather than at you.

  • warnLicensecopyleft/unknown — index-and-link only

    Whether the source repository declares an SPDX license permissive enough to redistribute.

How the grade is calculated

Each check contributes 0 points when it passes, 1 when it warns, and 2 when it fails. The total maps to a letter:

  • Aevery check passed
  • Bone warning
  • Ctwo warnings
  • Dprompt injection or body integrity failed, or three warnings
  • Fone of those failed, and something else is wrong

These are automated hygiene checks, not a security audit, and not a dependency or vulnerability scan. A grade of A means nothing was flagged — not that the artifact is safe.

Versions

  • git-22078e7db7b42026-07-31