Incorrect GPG package key on Debian package page

First I just wanted to mention how awesome you all are.

On the page for installing the Tor package on Ubuntu/Debian (, the signing GPG key for the Tor Project repo is listed as A3C4F0F979CAA22CDBA8F512EE8CBC9E886DDD89.asc, but this seems to be incorrect, as GPG doesn't recognize it. I assume this means that either it has been signed with a new key since, or that this is no longer the recommended path to install the Tor package (instead, maybe using Debian's official package is okay, as implied in Either way, please update the docs!

comment:1 Changed 5 months ago by pili

Thank you for reporting this. is an archived site and as such is not being updated and may contain outdated information.

Having said all that, we do have some instructions on installing tor on our support site: which list the same GPG key.

We will review these details but I believe they are correct.

comment:2 Changed 5 months ago by Belisarius

Clicking on the Documentation tab on the navbar on top still links to - you may want to consider taking that out.

This is the line I get when I try to add the keys:

wget -qO- | gpg --import
gpg: key EE8CBC9E886DDD89: 36 signatures not checked due to missing keys
gpg: key EE8CBC9E886DDD89: public key " archive signing key" imported
gpg: Total number processed: 1
gpg:               imported: 1
gpg: no ultimately trusted keys found

I hope that's helpful!

