[Mondo-devel] GPG keys are not correct for 'rhel7 x86_64 mondorescue Vanilla Packages'?

classic Classic list List threaded Threaded
3 messages Options
Reply | Threaded
Open this post in threaded view
|  
Report Content as Inappropriate

[Mondo-devel] GPG keys are not correct for 'rhel7 x86_64 mondorescue Vanilla Packages'?

KEINOS
Hi,

While installing 'Mondo Rescue' via `yum` into a fresh CentOS7,
I get a miss match error of GPG key for 'perl-ProjectBuilder-0.14.5-1.rhel7.noarch'.

> The GPG keys listed for the "rhel 7 x86_64 - mondorescue Vanilla Packages"
> repository are already installed but they are not correct for this package.
> Check that the correct key URLs are configured for this repository.
>
>  Failing package is: perl-ProjectBuilder-0.14.5-1.rhel7.noarch
>  GPG Keys are configured as:
>    ftp://ftp.mondorescue.org//rhel/7/x86_64/mondorescue.pubkey

Same thing happens even with the mirror server.

I checked the Wiki and the forums. And there were similar ones a few years ago and were all closed issue by configuring FTP settings by the repository's admin.

Is the repo's GPG (mondorescue.pubkey) file be the problem? or am I missing something?

My elder colleague says "It's been cracked so we shouldn't use it!",
but my guess is that 'perl-ProjectBuilder's GPG public key just isn't up-to-date.

So I decided to email here for an advice.

As an information,
if I install individually the 'perl-ProjectBuilder-0.14.5-1.rhel7.noarch'  via `rpm`,
and then installing 'Mondo Rescue' via `yum`, it installs with no problem.

The logs and detail infos are below.

Thanks,
KEINOS
--------------------------------------------------------

[OS: ] 
RedHat/CentOS 7.3.1611 Core, Vanilla

[ERROR: ]
Retrieving key from ftp://ftp.mondorescue.org//rhel/7/x86_64/mondorescue.pubkey
Importing GPG key 0x37DB9883:
 Userid     : "Bruno Cornec (primary address) <[hidden email]>"
 Fingerprint: 54aa 7ada 8c6b 0f5d 51c7 5dc0 141b 9ff2 37db 9883
 From       : ftp://ftp.mondorescue.org//rhel/7/x86_64/mondorescue.pubkey
Is this ok [y/N]: y
warning: /var/cache/yum/x86_64/7/mondorescue/packages/perl-ProjectBuilder-0.14.5-1.rhel7.noarch.rpm: Header V4 RSA/SHA512 Signature, key ID 20ebfb0e: NOKEY
Retrieving key from ftp://ftp.mondorescue.org//rhel/7/x86_64/mondorescue.pubkey


The GPG keys listed for the "rhel 7 x86_64 - mondorescue Vanilla Packages" repository are already installed but they are not correct for this package.
Check that the correct key URLs are configured for this repository.


 Failing package is: perl-ProjectBuilder-0.14.5-1.rhel7.noarch
 GPG Keys are configured as: ftp://ftp.mondorescue.org//rhel/7/x86_64/mondorescue.pubkey
[/ERROR]

[Steps that I took (as a root usr) : ][HERE]

yum -y update
cd /etc/yum.repos.d/
wget ftp://ftp.mondorescue.org/rhel/7/x86_64/mondorescue.repo
yum --enablerepo=mondorescue install mondo

[/HERE]

[Full log of the steps: ] ( I uploaded it to Gist )
https://gist.github.com/KEINOS/44bfac33d658843c95fcdc8fa57eb75f#file-20170718-1-error-full-log

[Other log files: ]
/var/log/mondoarchive.log :  n/a (not created)
/var/log/mindi.log :  n/a (not created)

[Other sites ( repo mirror) that failed also: ]
ftp://mondo.mirror.pclark.com/pub/mondorescue/rhel/7/x86_64/mondorescue.repo

[Steps that worked: ][HERE]

cd ~/
yum -y update
wget ftp://ftp.mondorescue.org/rhel/7/x86_64/perl-ProjectBuilder-0.14.5-1.rhel7.noarch.rpm
rpm -ivh perl-ProjectBuilder-0.14.5-1.rhel7.noarch.rpm

cd /etc/yum.repos.d/
wget ftp://ftp.mondorescue.org/rhel/7/x86_64/mondorescue.repo
yum --enablerepo=mondorescue install mondo

[/HERE]

EOF;

------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
Mondo-devel mailing list
[hidden email]
https://lists.sourceforge.net/lists/listinfo/mondo-devel
Reply | Threaded
Open this post in threaded view
|  
Report Content as Inappropriate

Re: [Mondo-devel] GPG keys are not correct for 'rhel7 x86_64 mondorescue Vanilla Packages'?

Bruno Cornec-4
KEINOS said on Tue, Jul 18, 2017 at 05:26:40PM +0900:
>While installing 'Mondo Rescue' via `yum` into a fresh CentOS7,
>I get a miss match error of GPG key for
>'perl-ProjectBuilder-0.14.5-1.rhel7.noarch'.

Well, I've changed my GPG Key (to comply with new requirements around GPG keys ans sha1 issues).

So the new packages such as this new version of pb are signed with my ne key while the old stayed signed with the old key.

>Is the repo's GPG (mondorescue.pubkey) file be the problem? or am I missing
>something?

In fact try to use the 2 .repo files, one for pb and the other for mondorescue as they should point to different key files (Cf: ftp://ftp.mondorescue.org/centos/7/x86_64/pb.repo and  ftp://ftp.mondorescue.org/centos/7/x86_64/mondorescue.repo) that way you should point to the right keys for the right pkgs. But you need to use the right repo for each install.

>My elder colleague says "It's been cracked so we shouldn't use it!",
>but my guess is that 'perl-ProjectBuilder's GPG public key just isn't
>up-to-date.

Well not cracked as far as I know. Just perl-ProjectBuilder is more up to date in fact :-)

All that will be solved when I'll publish 3.3.0 as all pkgs will have the new keys, that way yum won't have issues anymore.

Bruno.
--
HPE EMEA EG FLOSS Technology Strategist http://www.hpe.com/engage/opensource
Open Source Profession, WW Linux Community Lead    http://github.com/bcornec   
FLOSS projects:    http://mondorescue.org         http://project-builder.org
Musique ancienne?   http://www.musique-ancienne.org  http://www.medieval.org

------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
Mondo-devel mailing list
[hidden email]
https://lists.sourceforge.net/lists/listinfo/mondo-devel
Reply | Threaded
Open this post in threaded view
|  
Report Content as Inappropriate

Re: [Mondo-devel] GPG keys are not correct for 'rhel7 x86_64 mondorescue Vanilla Packages'?

Bruno Cornec-4
Bruno Cornec said on Wed, Aug 02, 2017 at 04:24:19PM +0200:
>All that will be solved when I'll publish 3.3.0 as all pkgs will have the new keys, that way yum won't have issues anymore.

And it's tracked here: http://trac.mondorescue.org/ticket/816

Bruno.
--
HPE EMEA EG FLOSS Technology Strategist http://www.hpe.com/engage/opensource
Open Source Profession, WW Linux Community Lead    http://github.com/bcornec   
FLOSS projects:    http://mondorescue.org         http://project-builder.org
Musique ancienne?   http://www.musique-ancienne.org  http://www.medieval.org

------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
_______________________________________________
Mondo-devel mailing list
[hidden email]
https://lists.sourceforge.net/lists/listinfo/mondo-devel
Loading...