Re: [Security-Discuss] Missing/Wrong gpg Keys
Vincent Danen <vdanen-7Aj/b8uzpy6AmYF/[email protected]>
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
On 7-Jan-05, at 2:08 AM, Simon Oosthoek wrote:
> just ran into this same problem on the server at work (running 10.0
> official)
>
> On Thu, Dec 30, 2004 at 11:44:45AM -0700, Vincent Danen wrote:
>> On 30-Dec-04, at 4:38 AM, Juergen Holm wrote:
>>
>>> The reson of this problem is: I've got no cooker pubkey in my rpm DB,
>>> because all of my PCs are installed from the official version.
>>> and
>>> only the *qt3* packages in updates/10.0/ are signed with the cooker
>>> key!
>>>
>>>> Maybe a better solution would be to put the pubkey from cooker into
>>>> updates; then if things from community get copied over, this won't
>>>> be
>>>> seen as a problem.
>>>
>>> Yes. That's it!
>>> But, if you put the cooker key in updates/.../base/pubkey or
>>> ../media_info/pubkey* (or whereever it has to go in 10.1)
>>> and I do an urpmi.update -f (or urpmi.removemedia, urpmi.addmedia)
>>> solves this the problem?
>>
>> It should. Doing an update should detect the new pubkey2 file.
>
> So when I run "urpmi.update -a" it should get the new key, but it
> doesn't...
>
> my urpmi.cfg for updates are:
> localupdates //data/mirror/updates/10.0/RPMS {
> hdlist: hdlist.localupdates.cz
> with_hdlist: ../base/hdlist.cz
> update
> }
>
> proxad-updates
> ftp://ftp.proxad.net/pub/Distributions_Linux/Mandrakelinux/official/
> updates/10.0/RPMS
> {
> hdlist: hdlist.proxad-updates.cz
> with_hdlist: ../base/hdlist.cz
> list: list.proxad-updates
> key-ids: 22458a98
> update
> }
Ummm... not sure why you're not getting it.
>>> So, is there a simple method to keep all the keys in the rpm DB
>>> uptodate or in sync for my 120 PCs?
>>>
>>> All this probs didn't arise if you have the strict policy:
>>>
>>> All packages in updates/ are sre signed by mandrake-sec only!
>>
>> Ummm... you weren't paying attention. The package was signed by our
>> key. There is a problem with older versions of rpm that don't replace
>> the header sig. The policy is in place. It's the tools that are
>> faulty.
>>
>
> How should this be fixed properly? Do I need to change something or is
> this
> waiting for an update to the tools?
Or you could just FTP the pubkey2 file and "rpm --import" it and be
done with it.
--
"lynx -source http://linsec.ca/vdanen.asc | gpg --import"
{FEE30AD4 : 7F6C A60C 06C2 4811 FA1C A2BC 2EBC 5E32 FEE3 0AD4}
PGP.sig
(application/pgp-signature, 186 B) - not displayed