Re: [Security-Discuss] Missing/Wrong gpg Keys
Simon Oosthoek <[email protected]>
| Newsgroups | gmane.linux.mandrake.security.general |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Jan 07, 2005 at 09:03:50PM -0700, Vincent Danen wrote: > > >>It should. Doing an update should detect the new pubkey2 file. > > > >So when I run "urpmi.update -a" it should get the new key, but it > >doesn't... > > > Ummm... not sure why you're not getting it. That's why I asked here... ;-) > >>>So, is there a simple method to keep all the keys in the rpm DB > >>>uptodate or in sync for my 120 PCs? > >>> > >>Ummm... you weren't paying attention. The package was signed by our > >>key. There is a problem with older versions of rpm that don't replace > >>the header sig. The policy is in place. It's the tools that are > >>faulty. > > > >How should this be fixed properly? Do I need to change something or is > >this > >waiting for an update to the tools? > > Or you could just FTP the pubkey2 file and "rpm --import" it and be > done with it. So the tools are broken, tools for ensuring the security of security fixes and bugfixes and to make it possible this be done automatically. And instead of updating the tools you suggest fixing it manually, like I'm using gentoo or slackware... (I had actually considered doing this, but I waited a bit more in hope of a proper fix) Vincent, I respect your work very much, but I'd say that Mandrakesoft should care a bit more about keeping up the user-friendlyness of the distro. I can file a bugreport about this, but it would help if you could help me narrow down the problem to a specific tool and perhaps even a solution so the bug report is specific enough to be fixed before the support period of 10.0 has run out :-/ Cheers Simon
message.footer
(text/plain, 239 B)
____________________________________________________ Want to buy your Pack or Services from MandrakeSoft? Go to http://www.mandrakestore.com Join the Club : http://www.mandrakeclub.com ____________________________________________________