If you are using the debian repository at repo.mosquitto.org you may have noticed that the repository signing key expired at the end of 2017. To get the updated key use the following commands:
wget http://repo.mosquitto.org/debian/mosquitto-repo.gpg.key sudo apt-key add mosquitto-repo.gpg.key