Re: [Security-Discuss] Missing/Wrong gpg Keys

Vincent Danen <vdanen-7Aj/b8uzpy6AmYF/[email protected]>
Newsgroups gmane.linux.mandrake.security.general
Message-ID <[email protected]>
On 7-Jan-05, at 2:08 AM, Simon Oosthoek wrote:

> just ran into this same problem on the server at work (running 10.0
> official)
>
> On Thu, Dec 30, 2004 at 11:44:45AM -0700, Vincent Danen wrote:
>> On 30-Dec-04, at 4:38 AM, Juergen Holm wrote:
>>
>>> The reson of this problem is: I've got no cooker pubkey in my rpm DB,
>>> because all of my PCs are installed from the official version.
>>> and
>>> only the *qt3* packages in updates/10.0/ are signed with the cooker
>>> key!
>>>
>>>> Maybe a better solution would be to put the pubkey from cooker into
>>>> updates; then if things from community get copied over, this won't  
>>>> be
>>>> seen as a problem.
>>>
>>> Yes. That's it!
>>> But, if you  put the cooker key in updates/.../base/pubkey or
>>> ../media_info/pubkey* (or whereever it has to go in 10.1)
>>> and I do an urpmi.update -f (or urpmi.removemedia, urpmi.addmedia)
>>> solves this the problem?
>>
>> It should.  Doing an update should detect the new pubkey2 file.
>
> So when I run "urpmi.update -a" it should get the new key, but it  
> doesn't...
>
> my urpmi.cfg for updates are:
> localupdates //data/mirror/updates/10.0/RPMS {
>   hdlist: hdlist.localupdates.cz
>   with_hdlist: ../base/hdlist.cz
>   update
> }
>
> proxad-updates
> ftp://ftp.proxad.net/pub/Distributions_Linux/Mandrakelinux/official/ 
> updates/10.0/RPMS
> {
>   hdlist: hdlist.proxad-updates.cz
>   with_hdlist: ../base/hdlist.cz
>   list: list.proxad-updates
>   key-ids: 22458a98
>   update
> }

Ummm... not sure why you're not getting it.

>>> So, is there a simple method to keep all the keys in the rpm DB
>>> uptodate or in sync for my 120 PCs?
>>>
>>> All this probs didn't arise if you have the strict policy:
>>>
>>> 	All packages in updates/ are sre signed by mandrake-sec only!
>>
>> Ummm... you weren't paying attention.  The package was signed by our
>> key.  There is a problem with older versions of rpm that don't replace
>> the header sig.  The policy is in place.  It's the tools that are
>> faulty.
>>
>
> How should this be fixed properly? Do I need to change something or is  
> this
> waiting for an update to the tools?

Or you could just FTP the pubkey2 file and "rpm --import" it and be  
done with it.

-- 
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C  A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig (application/pgp-signature, 186 B) - not displayed
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.