Re: [Security-Discuss] Missing/Wrong gpg Keys
Vincent Danen <vdanen-7Aj/b8uzpy6AmYF/[email protected]>
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
On 28-Dec-04, at 3:50 AM, Juergen Holm wrote: > I'm new to this list, because of: > > The updated packages *qt3*3.2.3-19.5.100mdk for 10.0 are signed by > "Mandrake Linux KDE Team <kde-7Aj/b8uzpy6AmYF/[email protected]>" Key ID > dd684d7a26752624 > but I don't find the public key. Is this from community? It can't be from updates. > Why isn't there a webfrontend to the MDK-Keyserver? > Exist a MDK-keyserver? URL? No, there doesn't (anymore). > Is there a recommended list of gpg-keys that should be installed? > Autoupdate with urpmi stopps for ever, if a key is missing! So, > security Updates will not be installed. Example: The keys that should be installed should be picked up by urpmi; they're on the mirrors as pubkey files. > kerberos update isn't installed with: "urpmi --auto-select --auto" > because of > /var/cache/urpmi/rpms/libqt3-3.2.3-19.5.100mdk.i586.rpm: Invalid > signature ((SHA1) DSA sha1 md5 gpg GPG#22458a98 NOT OK) > > So, this is really a PROBLEM! > > I suggest: > Publish a list of gpg-Keys and do NOT allow packages in > Mandrakelinux/official/updates signed with other keys. IIRC, packages going into community should be re-signed with a valid devel key. > Subscribing to this list may also be a problem, because the > "mandrakesecure.net" link on the bottom of > http://archives.mandrakelinux.com/ is dead! Yes, because mandrakesecure.net no longer exists. -- "lynx -source http://linsec.ca/vdanen.asc | gpg --import" {FEE30AD4 : 7F6C A60C 06C2 4811 FA1C A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig
(application/pgp-signature, 186 B) - not displayed