Hallo Ansgar, 04.11.19 09:44 Ansgar: Maybe apt could deprecate /etc/apt/trusted* and apt-key(8) in bullseye and abandon them in bullseye+1. The whole concept of having one keyring that authenticated all sources is wrong. I had my share in making /etc/apt/ trusted.d possible, but now that we have "Signed-By:" it is the inferior solution and thus not needed anymore. d-i should start to create sources.list with "Signed-By:" right now, #944102 [1]. apt or debian-archive-keyring could provide a migration script for sources.list entries without "Signed-By:" which could — at least for origin=Debian — add the correct "Signed-By:" option. Grüße Timo [1] https://bugs.debian.org/944102