Re: [Security-Discuss] Missing/Wrong gpg Keys

Vincent Danen <vdanen-7Aj/b8uzpy6AmYF/[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On 28-Dec-04, at 3:50 AM, Juergen Holm wrote:

> I'm new to this list, because of:
>
> The updated packages *qt3*3.2.3-19.5.100mdk  for 10.0 are signed by 
> "Mandrake Linux KDE Team <kde-7Aj/b8uzpy6AmYF/[email protected]>" Key ID 
> dd684d7a26752624
> but I don't find the public key.

Is this from community?  It can't be from updates.

> Why isn't there a webfrontend to the MDK-Keyserver?
> Exist a MDK-keyserver? URL?

No, there doesn't (anymore).

> Is there a recommended list of gpg-keys that should be installed?
> Autoupdate with urpmi stopps for ever, if a key is missing! So,
> security Updates will not be installed. Example:

The keys that should be installed should be picked up by urpmi; they're 
on the mirrors as pubkey files.

> kerberos update isn't installed with: "urpmi --auto-select --auto" 
> because of
> /var/cache/urpmi/rpms/libqt3-3.2.3-19.5.100mdk.i586.rpm: Invalid 
> signature ((SHA1) DSA sha1 md5 gpg GPG#22458a98 NOT OK)
>
> So, this is really a PROBLEM!
>
> I suggest:
> Publish a list of gpg-Keys and do NOT allow packages in 
> Mandrakelinux/official/updates signed with other keys.

IIRC, packages going into community should be re-signed with a valid 
devel key.

> Subscribing to this list may also be a problem, because the 
> "mandrakesecure.net" link on the bottom of 
> http://archives.mandrakelinux.com/ is dead!

Yes, because mandrakesecure.net no longer exists.

-- 
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C  A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig (application/pgp-signature, 186 B) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.