Re: [Security-Discuss] Missing/Wrong gpg Keys

Vincent Danen <vdanen-7Aj/b8uzpy6AmYF/[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On 30-Dec-04, at 4:38 AM, Juergen Holm wrote:

>>> Sisko:RPMS>rpm --checksig libqt3-3.2.3-19.5.100mdk.i586.rpm
>>> libqt3-3.2.3-19.5.100mdk.i586.rpm: (SHA1) DSA sha1 md5 gpg NOT OK
>> That keyid is for cooker.  Look at this:
>
> Yes you are right!
>
> The reson of this problem is: I've got no cooker pubkey in my rpm DB, 
> because all of my PCs are installed from the official version.
> and
> only the *qt3* packages in updates/10.0/ are signed with the cooker 
> key!
>
>> Maybe a better solution would be to put the pubkey from cooker into 
>> updates; then if things from community get copied over, this won't be 
>> seen as a problem.
>
> Yes. That's it!
> But, if you  put the cooker key in updates/.../base/pubkey or
> ../media_info/pubkey* (or whereever it has to go in 10.1)
> and I do an urpmi.update -f (or urpmi.removemedia, urpmi.addmedia)
> solves this the problem?

It should.  Doing an update should detect the new pubkey2 file.

> So, is there a simple method to keep all the keys in the rpm DB 
> uptodate or in sync for my 120 PCs?
>
> All this probs didn't arise if you have the strict policy:
>
> 	All packages in updates/ are sre signed by mandrake-sec only!

Ummm... you weren't paying attention.  The package was signed by our 
key.  There is a problem with older versions of rpm that don't replace 
the header sig.  The policy is in place.  It's the tools that are 
faulty.

-- 
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C  A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig (application/pgp-signature, 186 B) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.