The mistake, if I’ve found the correct issue, is definitely not good. Does APT support the design pattern that they use in TLS, where the “offline root” can have a very far future expiration date ...