Bug 1392714 - Missing signatures for 11 RPM packages
Summary: Missing signatures for 11 RPM packages
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Red Hat Enterprise Linux 7
Classification: Red Hat
Component: rhel-server-atomic
Version: 7.3
Hardware: x86_64
OS: Linux
high
high
Target Milestone: rc
: ---
Assignee: Colin Walters
QA Contact: atomic-bugs@redhat.com
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2016-11-08 05:03 UTC by Alex Jia
Modified: 2016-11-09 15:26 UTC (History)
1 user (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2016-11-09 15:20:11 UTC
Target Upstream Version:


Attachments (Terms of Use)

Description Alex Jia 2016-11-08 05:03:45 UTC
Description of problem:

The latest Atomic Host tree is missing signatures for these packages:

[root@atomic-host-test-986 cloud-user]# rpm -qai | grep -E '(Name|Signature)'|grep -B1 none
Name        : ostree-fuse
Signature   : (none)
--
Name        : cockpit-ostree
Signature   : (none)
--
Name        : nss-altfiles
Signature   : (none)
--
Name        : libsolv
Signature   : (none)
--
Name        : ostree
Signature   : (none)
--
Name        : rpm-ostree-client
Signature   : (none)
--
Name        : libgsystem
Signature   : (none)
--
Name        : atomic-devmode
Signature   : (none)
--
Name        : ostree-grub2
Signature   : (none)
--
Name        : cloud-utils-growpart
Signature   : (none)
--
Name        : redhat-release-atomic-host
Signature   : (none)



Version-Release number of selected component (if applicable):

[root@atomic-host-test-986 cloud-user]# cat /etc/redhat-release 
Red Hat Enterprise Linux Atomic Host release 7.3

[root@atomic-host-test-986 cloud-user]# atomic host status
State: idle
Deployments:
● rhel-atomic-host:rhel-atomic-host/7/x86_64/standard
       Version: 7.3.1 (2016-11-04 00:49:18)
        Commit: ad61697d3d0df9859551104d57c6187925f05e7daeffb41d4a276a9fed7e089d
        OSName: rhel-atomic-host

How reproducible:
always

Steps to Reproduce:
1. rpm -qai | grep Signature | cut -f3 -d"," | sed 's/Key ID//' | tr -s ' ' | cut -b10- | sort | uniq -c


Actual results:

[root@atomic-host-test-986 cloud-user]# rpm -qai | grep Signature | cut -f3 -d"," | sed 's/Key ID//' | tr -s ' ' | cut -b10- | sort | uniq -c
     16 f21541eb
    382 fd431d51
     11  : (none)


Expected results:


Additional info:

Missing signatures for 11 RPM packages and signatures are wrong for 16 RPM packages

the signatures are wrong for the following packages.

[root@atomic-host-test-986 cloud-user]# rpm -qai | grep -E '(Name|Signature)'|grep -B1 f21541eb
Name        : cockpit-shell
Signature   : RSA/SHA256, Wed 02 Nov 2016 09:13:00 PM UTC, Key ID 938a80caf21541eb
--
Name        : kubernetes-node
Signature   : RSA/SHA256, Wed 02 Nov 2016 09:13:48 PM UTC, Key ID 938a80caf21541eb
--
Name        : skopeo-containers
Signature   : RSA/SHA256, Wed 02 Nov 2016 09:14:13 PM UTC, Key ID 938a80caf21541eb
--
Name        : container-selinux
Signature   : RSA/SHA256, Wed 02 Nov 2016 09:13:02 PM UTC, Key ID 938a80caf21541eb
--
Name        : docker
Signature   : RSA/SHA256, Wed 02 Nov 2016 09:13:03 PM UTC, Key ID 938a80caf21541eb
--
Name        : atomic
Signature   : RSA/SHA256, Wed 02 Nov 2016 09:12:53 PM UTC, Key ID 938a80caf21541eb
--
Name        : docker-rhel-push-plugin
Signature   : RSA/SHA256, Wed 02 Nov 2016 09:13:17 PM UTC, Key ID 938a80caf21541eb
--
Name        : cockpit-docker
Signature   : RSA/SHA256, Wed 02 Nov 2016 09:12:58 PM UTC, Key ID 938a80caf21541eb
--
Name        : docker-novolume-plugin
Signature   : RSA/SHA256, Wed 02 Nov 2016 09:13:16 PM UTC, Key ID 938a80caf21541eb
--
Name        : docker-latest
Signature   : RSA/SHA256, Wed 02 Nov 2016 09:13:11 PM UTC, Key ID 938a80caf21541eb
--
Name        : kubernetes-client
Signature   : RSA/SHA256, Wed 02 Nov 2016 09:13:45 PM UTC, Key ID 938a80caf21541eb
--
Name        : cockpit-bridge
Signature   : RSA/SHA256, Wed 02 Nov 2016 09:12:55 PM UTC, Key ID 938a80caf21541eb
--
Name        : oci-systemd-hook
Signature   : RSA/SHA256, Wed 02 Nov 2016 09:14:00 PM UTC, Key ID 938a80caf21541eb
--
Name        : skopeo
Signature   : RSA/SHA256, Wed 02 Nov 2016 09:14:12 PM UTC, Key ID 938a80caf21541eb
--
Name        : docker-common
Signature   : RSA/SHA256, Wed 02 Nov 2016 09:13:09 PM UTC, Key ID 938a80caf21541eb
--
Name        : docker-lvm-plugin
Signature   : RSA/SHA256, Wed 02 Nov 2016 09:13:15 PM UTC, Key ID 938a80caf21541eb

Comment 2 Micah Abbott 2016-11-09 15:20:11 UTC
This is expected in pre-release composes where included packages are not in the REL PREP state and have not been signed.

Comment 3 Alex Jia 2016-11-09 15:26:53 UTC
(In reply to Micah Abbott from comment #2)
> This is expected in pre-release composes where included packages are not in
> the REL PREP state and have not been signed.

Micah, okay, thanks for update.


Note You need to log in before you can comment on or make changes to this bug.