# Ubuntu / Debian APT repository

The CH-J alpha repository publishes the official amd64 DEB package. It is intended for Ubuntu 24.04 and compatible desktop systems; compatibility with every Debian release is not guaranteed. The repository metadata is signed with the CH-J OpenPGP signing subkey held on a YubiKey. The private key is never uploaded to the webserver.

## Verify the key and enable the repository

The expected primary fingerprint is:

```text
0D92 778A D8EC F85C 80E3 9248 48F2 433A D9CD F453
```

Download the public key and inspect its fingerprint before installing it. Obtain the expected fingerprint independently from the CH-J README or an already trusted application copy.

```bash
curl -fsSLo ch-j-archive-keyring.gpg https://www.sm.ch-j.cz/apt/ch-j-archive-keyring.gpg
gpg --show-keys --with-fingerprint ch-j-archive-keyring.gpg
sudo install -d -m 0755 /etc/apt/keyrings
sudo install -m 0644 ch-j-archive-keyring.gpg /etc/apt/keyrings/ch-j-archive-keyring.gpg
```

Create `/etc/apt/sources.list.d/ch-j.sources`:

```text
Types: deb
URIs: https://www.sm.ch-j.cz/apt/
Suites: alpha
Components: main
Architectures: amd64
Signed-By: /etc/apt/keyrings/ch-j-archive-keyring.gpg
```

Then install:

```bash
sudo apt update
sudo apt install ch-j-server-manager
```

Later updates use `sudo apt update` followed by `sudo apt upgrade`. The version in the DEB control file increases for each release; prerelease identifiers use `~` so a later stable version sorts correctly. Each release also retains its unique application build ID. Only the alpha suite currently contains a package; beta and stable have signed empty indexes until an actual release is assigned to those channels.

## Guidance and license

APT cannot reliably display an interactive license before installation. On first launch and after an update, the application displays full CS/DE/EN operational guidance, followed by CH-J Proprietary Software License 1.14 and a required checkbox acknowledging the license terms and the data-loss/backup notice. Declining exits the application. The operational guidance remains informational and non-binding.

Use APT for updating repository installations. Do not start the application's separate installer during an APT transaction. The internal updater continues to support installations outside this repository.

Repository metadata uses `InRelease` and `Release.gpg`, SHA-256/SHA-512 indexes, and content-addressed indexes for consistent updates. `Signed-By` confines trust to this repository; do not use global `apt-key` trust or disable signature checks. Follow [Debian's third-party repository guidance](https://wiki.debian.org/DebianRepository/UseThirdParty).
