Re: [Security-Discuss] Missing/Wrong gpg Keys
Vincent Danen <vdanen-7Aj/b8uzpy6AmYF/[email protected]>
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
On 30-Dec-04, at 4:38 AM, Juergen Holm wrote:
>>> Sisko:RPMS>rpm --checksig libqt3-3.2.3-19.5.100mdk.i586.rpm
>>> libqt3-3.2.3-19.5.100mdk.i586.rpm: (SHA1) DSA sha1 md5 gpg NOT OK
>> That keyid is for cooker. Look at this:
>
> Yes you are right!
>
> The reson of this problem is: I've got no cooker pubkey in my rpm DB,
> because all of my PCs are installed from the official version.
> and
> only the *qt3* packages in updates/10.0/ are signed with the cooker
> key!
>
>> Maybe a better solution would be to put the pubkey from cooker into
>> updates; then if things from community get copied over, this won't be
>> seen as a problem.
>
> Yes. That's it!
> But, if you put the cooker key in updates/.../base/pubkey or
> ../media_info/pubkey* (or whereever it has to go in 10.1)
> and I do an urpmi.update -f (or urpmi.removemedia, urpmi.addmedia)
> solves this the problem?
It should. Doing an update should detect the new pubkey2 file.
> So, is there a simple method to keep all the keys in the rpm DB
> uptodate or in sync for my 120 PCs?
>
> All this probs didn't arise if you have the strict policy:
>
> All packages in updates/ are sre signed by mandrake-sec only!
Ummm... you weren't paying attention. The package was signed by our
key. There is a problem with older versions of rpm that don't replace
the header sig. The policy is in place. It's the tools that are
faulty.
--
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig
(application/pgp-signature, 186 B) - not displayed