Re: [Security-Discuss] Missing/Wrong gpg Keys

Vincent Danen <vdanen-7Aj/b8uzpy6AmYF/[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On 28-Dec-04, at 5:02 PM, Juergen Holm wrote:

>>> I'm new to this list, because of:
>>> The updated packages *qt3*3.2.3-19.5.100mdk  for 10.0 are signed by 
>>> "Mandrake Linux KDE Team <kde-7Aj/b8uzpy6AmYF/[email protected]>" Key ID 
>>> dd684d7a26752624
>>> but I don't find the public key.
>>
>> Is this from community?  It can't be from updates.
>
> It can:
>
> Date: 18 Aug 2004 23:23:55 -0000
> From: Mandrake Linux Security Team <[email protected]>
> Reply-To: security-discuss-J4tZAbal8pkzaQFa27Lw39BPR1lH4CV8@public.gmane.org
> To: security-announce-J4tZAbal8pkzaQFa27Lw39BPR1lH4CV8@public.gmane.org
> Subject: [Security Announce] MDKSA-2004:085 - Updated qt3 packages fix
> multiple vulnerabilities
>
> Sisko:RPMS>rpm --checksig libqt3-3.2.3-19.5.100mdk.i586.rpm
> libqt3-3.2.3-19.5.100mdk.i586.rpm: (SHA1) DSA sha1 md5 gpg NOT OK
> Sisko:RPMS>pwd
> /usr/rpm/Mandrakelinux/official/updates/10.0/RPMS
>
> For the Key ID see above. Updates are mirrored from 
> ftp.club-internet.fr

That keyid is for cooker.  Look at this:

[qateam@updates qateam]$ rpm --checksig *qt*
libqt3-3.2.3-19.5.100mdk.i586.rpm: (sha1) dsa sha1 md5 gpg OK
libqt3-devel-3.2.3-19.5.100mdk.i586.rpm: (sha1) dsa sha1 md5 gpg OK
libqt3-mysql-3.2.3-19.5.100mdk.i586.rpm: (sha1) dsa sha1 md5 gpg OK
libqt3-odbc-3.2.3-19.5.100mdk.i586.rpm: (sha1) dsa sha1 md5 gpg OK
libqt3-psql-3.2.3-19.5.100mdk.i586.rpm: (sha1) dsa sha1 md5 gpg OK
qt3-common-3.2.3-19.5.100mdk.i586.rpm: (sha1) dsa sha1 md5 gpg OK
qt3-example-3.2.3-19.5.100mdk.i586.rpm: (sha1) dsa sha1 md5 gpg OK
[qateam@updates qateam]$ cat /etc/mandrake-release
Mandrake Linux release 10.0 (Official) for i586
[qateam@updates qateam]$ rpm -Kv qt3-common-3.2.3-19.5.100mdk.i586.rpm
qt3-common-3.2.3-19.5.100mdk.i586.rpm:
     Header V3 DSA signature: OK, key ID 26752624
     Header SHA1 digest: OK (d5449321407a7c38944e12fbcd491d17ce739ef2)
     MD5 digest: OK (97a6e605dbd617486819a4f522ef754e)
     V3 DSA signature: OK, key ID 22458a98
[qateam@updates qateam]$ rpm -qi gpg-pubkey-26752624-3fd74faa
Name        : gpg-pubkey                   Relocations: (not 
relocatable)
Version     : 26752624                          Vendor: (none)
Release     : 3fd74faa                      Build Date: Wed 31 Mar 2004 
05:58:09 PM MST
Install Date: Wed 31 Mar 2004 05:58:09 PM MST      Build Host: localhost
Group       : Public Keys                   Source RPM: (none)
Size        : 0                                License: pubkey
Signature   : (none)
Summary     : gpg(MandrakeCooker <[email protected]>)
Description :
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: rpm-4.2.2 (beecrypt-3.0.0)

mQGiBD/XT6oRBADPpYAPClDtKLGSZKmDU3pI9XCrsa+sR3CAJgrscSsffDQFEV7VjgO520G3
+qBMG/ArgFHrJyFEWk4dNQsR7zRb8B+/ZFo3IhZKbk3gbjYsTrd05t4zDDYIS/GhWKHyhopK
6B9uhcKNbuAqA0fM9jDG2j46wmwtLpIrfLa/1SgQQwCgxF4Bdw4YoNhwUM98JTn3/Ojw8TcE
AKLxQsGCjLQNl4DTEev7w4BKzx95eCVnQ7r7XXldgVOgAxlywGYDJVQn3Zn9Ad4/+8g2wHXc
JxLNHUEIrsdZVqllzdYiQa27TtI3RLF09leKZQD1awX6sAZxYgCUlQhCukPc61FP3upyna0g
WFO6Jf/iS/PhZ96T00h2GliwePGTA/97g61DjVFKTlWUH1Bzz61rwtE3apsCX50W8J76Uris
ipl4niZC9Ns30ulyLUgLhTiCvdejqy9O1ONdH9W0ALwv1ThbRlo5I92rWLCwgUpko38qo1bS
NQ7DrCfKegKqiCpUltZ00gyUmAkKQTS9/nI/+lEKYkQJvY6ha5d3PC5SkLQqTWFuZHJha2VD
b29rZXIgPGNvb2tlckBsaW51eC1tYW5kcmFrZS5jb20+iF4EExECAB4FAj/XT6oCGwMGCwkI
BwMCAxUCAwMWAgECHgECF4AACgkQ3WhNeiZ1JiRczQCdGbsWsP/kMRVHdl1RKh8SRwpLeVcA
oKc6QNmnR5a7FvrBvF1+qeeOe/cXiEYEExECAAYFAj/XVeQACgkQ54mK4HB3H/OgQQCdECI6
SKQHUuNr5P2teLVkZzRRHtgAn04q+NhEnzdll0Ga3SjZyV3kkCxtiEYEExECAAYFAj/XV68A
CgkQRFk1+HjQGfXYaQCeK932DKZ/k7YNaFpE/RTDTVAE3uwAoKFJgC8DPPZUvF/9//kCG6ZI
mPKhuQENBD/XT6sQBAD5JPDpZ1toBcgDPsutvUfFBPJ0Iwi25p6rExQFssH7Pc9LVP1w/pXX
uenuW9d1WqivU6AhBC7hqgjhyf12WJ/rouM52w+RqqNtcIRK4gqHqYkuP54TD6bAXERC1eTJ
u4/XzZPRh5OR9FQSEmLGp7f662EqANPP3zZlE9El4zu1ywADBQQAvjEq5o0FD0zEoVhfjhsP
U/uHBG9JIwOPiWBWJlYnLefWgEU/qqGrq23bfBnHvrfS1nmBLId0j6BBhUhDWk2baP5GPcPb
9AKXsqUtTiJGFJaIJtVJ5FQT0jvHgcgaCRAfGBCe9zBCPzxV+jaEXI269n4VvGRpcK8uFTAw
iFnvzmWISQQYEQIACQUCP9dPqwIbDAAKCRDdaE16JnUmJIZUAKC45vNS3JYh5MPbW0UhOgw6
9M1sZgCfZI0GCIVleeEzgIx+eDBjS4zDtDV=
=NfCd
-----END PGP PUBLIC KEY BLOCK-----

[qateam@updates qateam]$ rpm -qi gpg-pubkey-26752624-3fd74faa|gpg 
--import
gpg: keyring `/home/qateam/.gnupg/secring.gpg' created
gpg: /home/qateam/.gnupg/trustdb.gpg: trustdb created
gpg: key 26752624: public key "MandrakeCooker 
<[email protected]>" imported
gpg: Total number processed: 1
gpg:               imported: 1
[qateam@updates qateam]$

I don't see "KDE team" anywhere.

>>> Why isn't there a webfrontend to the MDK-Keyserver?
>>> Exist a MDK-keyserver? URL?
>>
>> No, there doesn't (anymore).
>
> Right, not necessary if packages have KNOWN signs.

It does have known sigs.  That pubkey (for cooker) should be in 10.0 
community.  The updates key is in 10.0 updates.

>>> I suggest:
>>> Publish a list of gpg-Keys and do NOT allow packages in 
>>> Mandrakelinux/official/updates signed with other keys.
>>
>> IIRC, packages going into community should be re-signed with a valid 
>> devel key.
>
> Ok, please resign the .../updates/10.0/RPMS/*qt3* packages.

They will need to be rebuilt.  They were resigned.  If you look 
closely, you can see that two different keys are associated with those 
packages:

[qateam@updates qateam]$ rpm -Kv qt3-common-3.2.3-19.5.100mdk.i586.rpm
qt3-common-3.2.3-19.5.100mdk.i586.rpm:
     Header V3 DSA signature: OK, key ID 26752624
     Header SHA1 digest: OK (d5449321407a7c38944e12fbcd491d17ce739ef2)
     MD5 digest: OK (97a6e605dbd617486819a4f522ef754e)
     V3 DSA signature: OK, key ID 22458a98

The header sig is from the cooker key, the V3 DSA sig is from updates.

> How about an automatic check (rpm --checksig) for each new package in 
> updates/ ?
> The *qt3* prevent an automatic update of other sec updates, and THIS 
> is very dangerous!

This is already done, but as you can see from above, it passes here.  
We do a rpm -V on every package before it goes up to a) make sure it's 
signed and b) make sure it isn't corrupt.

Maybe a better solution would be to put the pubkey from cooker into 
updates; then if things from community get copied over, this won't be 
seen as a problem.

>>> Subscribing to this list may also be a problem, because the 
>>> "mandrakesecure.net" link on the bottom of 
>>> http://archives.mandrakelinux.com/ is dead!
>>
>> Yes, because mandrakesecure.net no longer exists.
>
> Yes, I saw the the "Not Found"

-- 
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C  A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig (application/pgp-signature, 186 B) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.