Re: [Security-Discuss] Missing/Wrong gpg Keys
Vincent Danen <vdanen-7Aj/b8uzpy6AmYF/[email protected]>
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
On 28-Dec-04, at 5:02 PM, Juergen Holm wrote: >>> I'm new to this list, because of: >>> The updated packages *qt3*3.2.3-19.5.100mdk for 10.0 are signed by >>> "Mandrake Linux KDE Team <kde-7Aj/b8uzpy6AmYF/[email protected]>" Key ID >>> dd684d7a26752624 >>> but I don't find the public key. >> >> Is this from community? It can't be from updates. > > It can: > > Date: 18 Aug 2004 23:23:55 -0000 > From: Mandrake Linux Security Team <[email protected]> > Reply-To: security-discuss-J4tZAbal8pkzaQFa27Lw39BPR1lH4CV8@public.gmane.org > To: security-announce-J4tZAbal8pkzaQFa27Lw39BPR1lH4CV8@public.gmane.org > Subject: [Security Announce] MDKSA-2004:085 - Updated qt3 packages fix > multiple vulnerabilities > > Sisko:RPMS>rpm --checksig libqt3-3.2.3-19.5.100mdk.i586.rpm > libqt3-3.2.3-19.5.100mdk.i586.rpm: (SHA1) DSA sha1 md5 gpg NOT OK > Sisko:RPMS>pwd > /usr/rpm/Mandrakelinux/official/updates/10.0/RPMS > > For the Key ID see above. Updates are mirrored from > ftp.club-internet.fr That keyid is for cooker. Look at this: [qateam@updates qateam]$ rpm --checksig *qt* libqt3-3.2.3-19.5.100mdk.i586.rpm: (sha1) dsa sha1 md5 gpg OK libqt3-devel-3.2.3-19.5.100mdk.i586.rpm: (sha1) dsa sha1 md5 gpg OK libqt3-mysql-3.2.3-19.5.100mdk.i586.rpm: (sha1) dsa sha1 md5 gpg OK libqt3-odbc-3.2.3-19.5.100mdk.i586.rpm: (sha1) dsa sha1 md5 gpg OK libqt3-psql-3.2.3-19.5.100mdk.i586.rpm: (sha1) dsa sha1 md5 gpg OK qt3-common-3.2.3-19.5.100mdk.i586.rpm: (sha1) dsa sha1 md5 gpg OK qt3-example-3.2.3-19.5.100mdk.i586.rpm: (sha1) dsa sha1 md5 gpg OK [qateam@updates qateam]$ cat /etc/mandrake-release Mandrake Linux release 10.0 (Official) for i586 [qateam@updates qateam]$ rpm -Kv qt3-common-3.2.3-19.5.100mdk.i586.rpm qt3-common-3.2.3-19.5.100mdk.i586.rpm: Header V3 DSA signature: OK, key ID 26752624 Header SHA1 digest: OK (d5449321407a7c38944e12fbcd491d17ce739ef2) MD5 digest: OK (97a6e605dbd617486819a4f522ef754e) V3 DSA signature: OK, key ID 22458a98 [qateam@updates qateam]$ rpm -qi gpg-pubkey-26752624-3fd74faa Name : gpg-pubkey Relocations: (not relocatable) Version : 26752624 Vendor: (none) Release : 3fd74faa Build Date: Wed 31 Mar 2004 05:58:09 PM MST Install Date: Wed 31 Mar 2004 05:58:09 PM MST Build Host: localhost Group : Public Keys Source RPM: (none) Size : 0 License: pubkey Signature : (none) Summary : gpg(MandrakeCooker <[email protected]>) Description : -----BEGIN PGP PUBLIC KEY BLOCK----- Version: rpm-4.2.2 (beecrypt-3.0.0) mQGiBD/XT6oRBADPpYAPClDtKLGSZKmDU3pI9XCrsa+sR3CAJgrscSsffDQFEV7VjgO520G3 +qBMG/ArgFHrJyFEWk4dNQsR7zRb8B+/ZFo3IhZKbk3gbjYsTrd05t4zDDYIS/GhWKHyhopK 6B9uhcKNbuAqA0fM9jDG2j46wmwtLpIrfLa/1SgQQwCgxF4Bdw4YoNhwUM98JTn3/Ojw8TcE AKLxQsGCjLQNl4DTEev7w4BKzx95eCVnQ7r7XXldgVOgAxlywGYDJVQn3Zn9Ad4/+8g2wHXc JxLNHUEIrsdZVqllzdYiQa27TtI3RLF09leKZQD1awX6sAZxYgCUlQhCukPc61FP3upyna0g WFO6Jf/iS/PhZ96T00h2GliwePGTA/97g61DjVFKTlWUH1Bzz61rwtE3apsCX50W8J76Uris ipl4niZC9Ns30ulyLUgLhTiCvdejqy9O1ONdH9W0ALwv1ThbRlo5I92rWLCwgUpko38qo1bS NQ7DrCfKegKqiCpUltZ00gyUmAkKQTS9/nI/+lEKYkQJvY6ha5d3PC5SkLQqTWFuZHJha2VD b29rZXIgPGNvb2tlckBsaW51eC1tYW5kcmFrZS5jb20+iF4EExECAB4FAj/XT6oCGwMGCwkI BwMCAxUCAwMWAgECHgECF4AACgkQ3WhNeiZ1JiRczQCdGbsWsP/kMRVHdl1RKh8SRwpLeVcA oKc6QNmnR5a7FvrBvF1+qeeOe/cXiEYEExECAAYFAj/XVeQACgkQ54mK4HB3H/OgQQCdECI6 SKQHUuNr5P2teLVkZzRRHtgAn04q+NhEnzdll0Ga3SjZyV3kkCxtiEYEExECAAYFAj/XV68A CgkQRFk1+HjQGfXYaQCeK932DKZ/k7YNaFpE/RTDTVAE3uwAoKFJgC8DPPZUvF/9//kCG6ZI mPKhuQENBD/XT6sQBAD5JPDpZ1toBcgDPsutvUfFBPJ0Iwi25p6rExQFssH7Pc9LVP1w/pXX uenuW9d1WqivU6AhBC7hqgjhyf12WJ/rouM52w+RqqNtcIRK4gqHqYkuP54TD6bAXERC1eTJ u4/XzZPRh5OR9FQSEmLGp7f662EqANPP3zZlE9El4zu1ywADBQQAvjEq5o0FD0zEoVhfjhsP U/uHBG9JIwOPiWBWJlYnLefWgEU/qqGrq23bfBnHvrfS1nmBLId0j6BBhUhDWk2baP5GPcPb 9AKXsqUtTiJGFJaIJtVJ5FQT0jvHgcgaCRAfGBCe9zBCPzxV+jaEXI269n4VvGRpcK8uFTAw iFnvzmWISQQYEQIACQUCP9dPqwIbDAAKCRDdaE16JnUmJIZUAKC45vNS3JYh5MPbW0UhOgw6 9M1sZgCfZI0GCIVleeEzgIx+eDBjS4zDtDV= =NfCd -----END PGP PUBLIC KEY BLOCK----- [qateam@updates qateam]$ rpm -qi gpg-pubkey-26752624-3fd74faa|gpg --import gpg: keyring `/home/qateam/.gnupg/secring.gpg' created gpg: /home/qateam/.gnupg/trustdb.gpg: trustdb created gpg: key 26752624: public key "MandrakeCooker <[email protected]>" imported gpg: Total number processed: 1 gpg: imported: 1 [qateam@updates qateam]$ I don't see "KDE team" anywhere. >>> Why isn't there a webfrontend to the MDK-Keyserver? >>> Exist a MDK-keyserver? URL? >> >> No, there doesn't (anymore). > > Right, not necessary if packages have KNOWN signs. It does have known sigs. That pubkey (for cooker) should be in 10.0 community. The updates key is in 10.0 updates. >>> I suggest: >>> Publish a list of gpg-Keys and do NOT allow packages in >>> Mandrakelinux/official/updates signed with other keys. >> >> IIRC, packages going into community should be re-signed with a valid >> devel key. > > Ok, please resign the .../updates/10.0/RPMS/*qt3* packages. They will need to be rebuilt. They were resigned. If you look closely, you can see that two different keys are associated with those packages: [qateam@updates qateam]$ rpm -Kv qt3-common-3.2.3-19.5.100mdk.i586.rpm qt3-common-3.2.3-19.5.100mdk.i586.rpm: Header V3 DSA signature: OK, key ID 26752624 Header SHA1 digest: OK (d5449321407a7c38944e12fbcd491d17ce739ef2) MD5 digest: OK (97a6e605dbd617486819a4f522ef754e) V3 DSA signature: OK, key ID 22458a98 The header sig is from the cooker key, the V3 DSA sig is from updates. > How about an automatic check (rpm --checksig) for each new package in > updates/ ? > The *qt3* prevent an automatic update of other sec updates, and THIS > is very dangerous! This is already done, but as you can see from above, it passes here. We do a rpm -V on every package before it goes up to a) make sure it's signed and b) make sure it isn't corrupt. Maybe a better solution would be to put the pubkey from cooker into updates; then if things from community get copied over, this won't be seen as a problem. >>> Subscribing to this list may also be a problem, because the >>> "mandrakesecure.net" link on the bottom of >>> http://archives.mandrakelinux.com/ is dead! >> >> Yes, because mandrakesecure.net no longer exists. > > Yes, I saw the the "Not Found" -- "lynx -source http://linsec.ca/vdanen.asc | gpg --import" {FEE30AD4 : 7F6C A60C 06C2 4811 FA1C A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig
(application/pgp-signature, 186 B) - not displayed