Re: [Security-Discuss] Invalid signature on perl-URPM-1.03-2mdk.i586.rpm
Vincent Danen <vdanen-7Aj/b8uzpy6AmYF/[email protected]>
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
On 17-Dec-04, at 5:44 PM, Michael Riß wrote:
> Vincent Danen wrote:
>> Yes, and it's a bogus report. There's nothing wrong with the file.
>> Look at my comments on the report and you'll see that, unlike the
>> poster and some other people, I went through and actually *checked*
>> to see what the problem was. And there was none.
>
> Hello Vincent
>
> On my machine 10.1 i586 I have these two files:
>
> f9d5f30016da51c6afd8bbd1a7b19246 urpmi-4.5-29.1.101mdk.noarch.rpm
> 74faac228fb76a182ead8df7eaf3534f perl-URPM-1.03-2mdk.i586.rpm
>
> urpmi-4.5-29.1.101mdk.noarch.rpm is signed correctly
> perl-URPM-1.03-2mdk.i586.rpm is not.
>
> # rpm -K urpmi-4.5-29.1.101mdk.noarch.rpm
> urpmi-4.5-29.1.101mdk.noarch.rpm: sha1 md5 gpg OK
>
> # rpm -K perl-URPM-1.03-2mdk.i586.rpm
> perl-URPM-1.03-2mdk.i586.rpm: (SHA1) DSA sha1 md5 gpg NOT OK
>
> # rpm -Kv urpmi-4.5-29.1.101mdk.noarch.rpm
> urpmi-4.5-29.1.101mdk.noarch.rpm:
> Header SHA1 digest: OK (76b651e16eadb02cd20a631afbd2d34727f6d8dc)
> MD5 digest: OK (d88179c2ecda8a099ea591a4f8e5cd31)
> V3 DSA signature: OK, key ID 22458a98
>
> # rpm -Kv perl-URPM-1.03-2mdk.i586.rpm
> perl-URPM-1.03-2mdk.i586.rpm:
> Header V3 DSA signature: NOKEY, key ID 26752624
> Header SHA1 digest: OK (4e2a23f8e715d734828cc63a6afaafe52d8dbf61)
> MD5 digest: OK (8b421caba12ffb32267c6110eea5b684)
> V3 DSA signature: OK, key ID 22458a98
>
> There is the additional V3 DSA signature with key ID 26752624.
> It seems to be the cooker key:
> http://pgp.mit.edu:11371/pks/lookup?search=0x26752624&op=index
> I guess this causes the trouble as the cooker key isn't present
> on stock 10.1 machines.
This is the data I like to see. Ok, looked again. Seems like rpm is
being a little strange. On CS2.1 (the host machine), the rpm is
properly attributed to the right key (the security team key), but with
the 10.1 rpm, the key is being attributed to the cooker key.
So resigning the file didn't work; at least not for the distro it was
supposed to work for.
This makes for a bit of a pickle... guess I'm recompiling perl-URPM
tonight.
Thanks for doing further digging... I appreciate the depth you went
into (better than most).
--
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig
(application/pgp-signature, 186 B) - not displayed