Symptoms & scope
- pacman reports a signer with unknown trust.
- A transaction stops with invalid or corrupted package (PGP signature).
Relevant environment
Arch Linux official package signatures; other pacman-based distributions use their own trust roots and keyring packages.
Recognizable messages (synthetic examples)
error: example-package: signature from "Example Packager <example@archlinux.org>" is unknown trustVerify its full fingerprint and distribution trust chain; this is not evidence that arbitrary local signing is safe.
error: failed to commit transaction (invalid or corrupted package (PGP signature))Check earlier signer/clock/download messages; this summary does not distinguish stale trust from altered content.
Possible causes
These are possible explanations, not a confirmed diagnosis. Several independent faults can coexist.
- The installed distribution keyring may not include a legitimate current signer or trust update.
- Incorrect time or a damaged/tampered download may invalidate signature verification.
Diagnose safely
Run one command at a time in the relevant session. Read the explanation first. Uppercase placeholders need your own values; tools and privileges vary by distribution. These commands are displayed here and never executed by the website.
Check 1
Queries the local official Arch keyring package version; use the distribution’s own keyring name elsewhere.
pacman -Q archlinux-keyringInterpret the result: A missing or old keyring supports a trust-update issue, but version alone cannot establish the authenticity of the failed download.
Check 2
Reads wall clock, timezone and synchronization status; does not change the clock. On non-systemd systems use date -u.
timedatectl statusInterpret the result: A large time error can make a valid signature appear expired or not yet valid. Synchronized status is not an independent signer verification.
Check 3
Replace KEY_ID with the signer ID from the error; lists known fingerprints without importing, signing or refreshing keys. Keyring read access may require privileges.
pacman-key --finger KEY_IDInterpret the result: Compare the full fingerprint with the distribution’s published signer. Missing keys and unknown trust are different from a verified signature on a damaged package.
Evidence-guided next steps
Refresh the official distribution keyring through its trust chain
If the signer is legitimate and the keyring is outdated, use Arch’s documented keyring-first recovery procedure and then complete the full system upgrade immediately. If the existing keyring cannot verify its own update, use verified recovery media and the distribution’s documented trust bootstrap.
Precautions: Do not locally sign an unknown key or set SigLevel=Never. A keyserver response alone does not establish a trusted packager.
Recovery / rollback: Restore a saved coherent recovery snapshot if the bootstrap was incorrect; preserve authenticated verification instead of reverting to an obsolete trust bypass.
Did this solution help you?
Correct confirmed time drift or replace the failed archive
If time is wrong, restore the approved time-synchronization setup before retrying. If the signer is verified and only one cached archive fails, move that exact archive aside and redownload it through the configured trusted mirror during the next reviewed transaction. Keep the original for comparison.
Precautions: Do not purge the entire cache or install the rejected archive with signature checking disabled. Persistent failures require checking mirror/content provenance.
Recovery / rollback: Restore the prior time-service configuration if changed incorrectly; retain the rejected archive separately rather than reinstalling an unverifiable package.
Did this solution help you?
References & review
This guide was prepared from primary project or distribution sources and reviewed on the date shown. This is an editorial source check, not evidence that a fix was reproduced on your hardware. Diagnostic log examples are synthetic fixtures. Version-dependent details must be checked against your installed release.
- Arch pacman-key: fingerprints and trust operations (project or distribution documentation)
- Arch pacman.conf: repositories and signature checking (project or distribution documentation)
- ArchWiki: package signing and keyring maintenance (project or distribution documentation)