Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 167902

Summary: Corrupt gpg key in package
Product: [Retired] Fedora Infrastructure Reporter: Kenneth Porter <shiva>
Component: otherAssignee: Bill Nottingham <notting>
Status: CLOSED WONTFIX QA Contact: Bill Nottingham <notting>
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: florin, nobody+pnasrat, rvokal
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2008-05-16 20:57:28 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Kenneth Porter 2005-09-09 11:13:55 UTC
Attempting to install anaconda-help with "yum install anaconda-help" (using a
local repository) results in the following error message:

warning: rpmts_HdrFromFdno: Header V3 DSA signature: NOKEY, key ID db42a60e
public key not available for anaconda-help-10.1.0-1.noarch.rpm
Retrieving GPG key from file:///etc/pki/rpm-gpg/RPM-GPG-KEY-fedora

The GPG key at file:///etc/pki/rpm-gpg/RPM-GPG-KEY-fedora (0x4F2A6FD2)
is already installed but is not the correct key for this package.
Check that this is the correct key for the "Fedora Core 4 - i386 - Base" repository.

Comment 1 Kenneth Porter 2005-09-09 11:15:27 UTC
Workaround is to temporarily set gpgcheck=0 in /etc/yum.repos.d/fedora.repo.

Comment 2 Paul Nasrat 2005-09-09 11:41:05 UTC
Due to the way the tree inheritence works some ( a very small number of noarch)
packages ended up not being rebuilt so are signed with the Red Hat key

rpm --import /etc/pki/rpm-gpg/RPM-GPG-KEY

Bill, I'm pretty sure something like repoclosure could pick this up pre ship to
prevent this in FC5

Comment 3 Bill Nottingham 2005-09-09 18:52:42 UTC
Repoclosure can check sigs?

Comment 4 Paul Nasrat 2005-09-09 19:03:35 UTC
If it can't atm it shouldn't be too painful

Comment 5 Bill Nottingham 2005-09-09 19:24:55 UTC
Hm, I don't see the signature in the repodata anywhere. Perhaps I'm looking at
the wrong place?

Comment 6 Paul Nasrat 2005-09-09 19:44:49 UTC
No we'd have to download the headers and run a test transaction but it's not a
hard script to write with the yum api. I'll see if I can knock something up over
the weekend.

Comment 7 Bill Nottingham 2005-09-09 19:47:54 UTC
Why not embrace and extend the metadata format with the key the package is
signed with?

Comment 8 Seth Vidal 2005-09-12 23:44:16 UTC
What good would it do to put the key in the metadata?

Just so you can check the repo based on the metadata? why not make repo
maintainers take some care in creating their repositories?


Comment 9 Bill Nottingham 2005-09-13 03:52:50 UTC
Having it in the metadata makes it easy to check at the same time that you're
checking a repo for dependency closure, and other sanity checks.

Comment 10 Bill Nottingham 2005-10-31 20:07:48 UTC
*** Bug 162302 has been marked as a duplicate of this bug. ***

Comment 11 Bill Nottingham 2008-05-16 20:57:28 UTC
Closing, I don't think we're going to do this.