Bug 2184994
| Summary: | virt-builder fails to validate SHA1 GPG key (gpg: Note: signatures using the SHA1 algorithm are rejected) | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 9 | Reporter: | YongkuiGuo <yoguo> |
| Component: | guestfs-tools | Assignee: | Richard W.M. Jones <rjones> |
| Status: | CLOSED MIGRATED | QA Contact: | YongkuiGuo <yoguo> |
| Severity: | medium | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 9.3 | CC: | lersek, rjones, virt-maint |
| Target Milestone: | rc | Keywords: | MigratedToJIRA, Triaged |
| Target Release: | --- | Flags: | pm-rhel:
mirror+
|
| Hardware: | Unspecified | ||
| OS: | Unspecified | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | If docs needed, set a value | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2023-09-22 13:30:37 UTC | Type: | Bug |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
YongkuiGuo
2023-04-06 12:23:24 UTC
Since I just a few minutes ago added guestfs-tools 1.50.1, could you try that version? See bug 2168626 (In reply to Richard W.M. Jones from comment #1) > Since I just a few minutes ago added guestfs-tools 1.50.1, could you try > that version? > See bug 2168626 I just tried, guestfs-tools-1.50.1 cannot fix this issue. This seems like it could be something to do with SHA1. However I'm not sure
how to show the full information of a GPG key. eg: This only gives
superficial info:
$ gpg --show-keys /etc/virt-builder/repos.d/libguestfs.gpg
pub rsa4096 2011-10-11 [SC]
F7774FB1AD074A7E8C8767EA91738F73E1B768A0
uid Richard W.M. Jones <rjones>
uid Richard W.M. Jones <rich>
sub rsa4096 2011-10-11 [E]
From "builder/sigchecker.ml" @ b68a846e2f40: the "--trusted-key" gpg option gets the '' (empty string) operand because the previous import fails. gpg never prints "IMPORTED", so we never set "key_id" to the imported key, key_id remains the empty string. I figure we need to update "/etc/virt-builder/repos.d/libguestfs.gpg" so that it provide keys with SHA256 signatures. 3rd time lucky ... Apparently using -vv shows more detail:
$ gpg -vv --show-keys /etc/virt-builder/repos.d/libguestfs.gpg
gpg: armor: BEGIN PGP PUBLIC KEY BLOCK
gpg: armor header: Version: GnuPG v1.4.14 (GNU/Linux)
# off=0 ctb=99 tag=6 hlen=3 plen=525
:public key packet:
version 4, algo 1, created 1318334657, expires 0
pkey[0]: [4096 bits]
pkey[1]: [17 bits]
keyid: 91738F73E1B768A0
# off=528 ctb=b4 tag=13 hlen=2 plen=37
:user ID packet: "Richard W.M. Jones <rich>"
# off=567 ctb=89 tag=2 hlen=3 plen=568
:signature packet: algo 1, keyid 91738F73E1B768A0
version 4, created 1318334657, md5len 0, sigclass 0x13
digest algo 2, begin of digest 74 18
hashed subpkt 2 len 4 (sig created 2011-10-11)
hashed subpkt 27 len 1 (key flags: 03)
hashed subpkt 11 len 5 (pref-sym-algos: 9 8 7 3 2)
hashed subpkt 21 len 5 (pref-hash-algos: 8 2 9 10 11)
hashed subpkt 22 len 3 (pref-zip-algos: 2 3 1)
hashed subpkt 30 len 1 (features: 01)
hashed subpkt 23 len 1 (keyserver preferences: 80)
subpkt 16 len 8 (issuer key ID 91738F73E1B768A0)
data: [4092 bits]
# off=1138 ctb=b4 tag=13 hlen=2 plen=38
:user ID packet: "Richard W.M. Jones <rjones>"
# off=1178 ctb=89 tag=2 hlen=3 plen=568
:signature packet: algo 1, keyid 91738F73E1B768A0
version 4, created 1318336779, md5len 0, sigclass 0x13
digest algo 2, begin of digest 21 46
hashed subpkt 2 len 4 (sig created 2011-10-11)
hashed subpkt 27 len 1 (key flags: 03)
hashed subpkt 11 len 5 (pref-sym-algos: 9 8 7 3 2)
hashed subpkt 21 len 5 (pref-hash-algos: 8 2 9 10 11)
hashed subpkt 22 len 3 (pref-zip-algos: 2 3 1)
hashed subpkt 30 len 1 (features: 01)
hashed subpkt 23 len 1 (keyserver preferences: 80)
subpkt 16 len 8 (issuer key ID 91738F73E1B768A0)
data: [4096 bits]
# off=1749 ctb=b9 tag=14 hlen=3 plen=525
:public sub key packet:
version 4, algo 1, created 1318334657, expires 0
pkey[0]: [4096 bits]
pkey[1]: [17 bits]
keyid: 9658E5232D07308A
# off=2277 ctb=89 tag=2 hlen=3 plen=543
:signature packet: algo 1, keyid 91738F73E1B768A0
version 4, created 1318334657, md5len 0, sigclass 0x18
digest algo 2, begin of digest 48 b4
hashed subpkt 2 len 4 (sig created 2011-10-11)
hashed subpkt 27 len 1 (key flags: 0C)
subpkt 16 len 8 (issuer key ID 91738F73E1B768A0)
data: [4095 bits]
pub rsa4096 2011-10-11 [SC]
F7774FB1AD074A7E8C8767EA91738F73E1B768A0
uid Richard W.M. Jones <rjones>
uid Richard W.M. Jones <rich>
sub rsa4096 2011-10-11 [E]
In my env:
$ gpg -vv --show-keys /etc/virt-builder/repos.d/libguestfs.gpg
gpg: Note: RFC4880bis features are enabled.
gpg: armor: BEGIN PGP PUBLIC KEY BLOCK
gpg: armor header: Version: GnuPG v1.4.14 (GNU/Linux)
# off=0 ctb=99 tag=6 hlen=3 plen=525
:public key packet:
version 4, algo 1, created 1318334657, expires 0
pkey[0]: [4096 bits]
pkey[1]: [17 bits]
keyid: 91738F73E1B768A0
# off=528 ctb=b4 tag=13 hlen=2 plen=37
:user ID packet: "Richard W.M. Jones <rich>"
# off=567 ctb=89 tag=2 hlen=3 plen=568
:signature packet: algo 1, keyid 91738F73E1B768A0
version 4, created 1318334657, md5len 0, sigclass 0x13
digest algo 2, begin of digest 74 18
hashed subpkt 2 len 4 (sig created 2011-10-11)
hashed subpkt 27 len 1 (key flags: 03)
hashed subpkt 11 len 5 (pref-sym-algos: 9 8 7 3 2)
hashed subpkt 21 len 5 (pref-hash-algos: 8 2 9 10 11)
hashed subpkt 22 len 3 (pref-zip-algos: 2 3 1)
hashed subpkt 30 len 1 (features: 01)
hashed subpkt 23 len 1 (keyserver preferences: 80)
subpkt 16 len 8 (issuer key ID 91738F73E1B768A0)
data: [4092 bits]
# off=1138 ctb=b4 tag=13 hlen=2 plen=38
:user ID packet: "Richard W.M. Jones <rjones>"
# off=1178 ctb=89 tag=2 hlen=3 plen=568
:signature packet: algo 1, keyid 91738F73E1B768A0
version 4, created 1318336779, md5len 0, sigclass 0x13
digest algo 2, begin of digest 21 46
hashed subpkt 2 len 4 (sig created 2011-10-11)
hashed subpkt 27 len 1 (key flags: 03)
hashed subpkt 11 len 5 (pref-sym-algos: 9 8 7 3 2)
hashed subpkt 21 len 5 (pref-hash-algos: 8 2 9 10 11)
hashed subpkt 22 len 3 (pref-zip-algos: 2 3 1)
hashed subpkt 30 len 1 (features: 01)
hashed subpkt 23 len 1 (keyserver preferences: 80)
subpkt 16 len 8 (issuer key ID 91738F73E1B768A0)
data: [4096 bits]
# off=1749 ctb=b9 tag=14 hlen=3 plen=525
:public sub key packet:
version 4, algo 1, created 1318334657, expires 0
pkey[0]: [4096 bits]
pkey[1]: [17 bits]
keyid: 9658E5232D07308A
# off=2277 ctb=89 tag=2 hlen=3 plen=543
:signature packet: algo 1, keyid 91738F73E1B768A0
version 4, created 1318334657, md5len 0, sigclass 0x18
digest algo 2, begin of digest 48 b4
hashed subpkt 2 len 4 (sig created 2011-10-11)
hashed subpkt 27 len 1 (key flags: 0C)
subpkt 16 len 8 (issuer key ID 91738F73E1B768A0)
data: [4095 bits]
gpg: Note: signatures using the SHA1 algorithm are rejected
gpg: key 91738F73E1B768A0: invalid self-signature on user ID "Richard W.M. Jones <rich>"
gpg: key 91738F73E1B768A0: invalid self-signature on user ID "Richard W.M. Jones <rjones>"
gpg: key 91738F73E1B768A0/9658E5232D07308A: invalid subkey binding
gpg: key 91738F73E1B768A0: skipped user ID "Richard W.M. Jones <rich>"
gpg: key 91738F73E1B768A0: skipped user ID "Richard W.M. Jones <rjones>"
gpg: key 91738F73E1B768A0/9658E5232D07308A: skipped subkey
pub rsa4096 2011-10-11 [SCEA]
F7774FB1AD074A7E8C8767EA91738F73E1B768A0
(In reply to Richard W.M. Jones from comment #3) > This seems like it could be something to do with SHA1. Right; from comment#0: "gpg: Note: signatures using the SHA1 algorithm are rejected". > However I'm not sure > how to show the full information of a GPG key. eg: This only gives > superficial info: > > $ gpg --show-keys /etc/virt-builder/repos.d/libguestfs.gpg I didn't expect it to be this complicated, but it is... <https://stackoverflow.com/questions/22136029/how-to-display-gpg-key-details-without-importing-it> leads me to pgpdump (available in Fedora and EPEL), and then: pgpdump /etc/virt-builder/repos.d/libguestfs.gpg will print a bunch of "Hash alg - SHA1(hash 2)" entries under "Signature Packet"s. Basically pgpdump is a wrapper around "gpg --list-packets", and it translates the algorithm references in the "--list-packets" output to names, from RFC 4880. SHA-1 is "hash algorithm 2", so wherever you see "digest algo 2" in the untranslated output above, that's where pgpdump will print "Hash alg - SHA1(hash 2)". Dist-git change: 464efce3c538 ("Mark SHA1 as a weak digest", 2023-03-30).
For bug 2070722.
From reading the downstream gnupg2 source code: please try with the "--allow-weak-digest-algos" command line option. ... in the prepped source of gnupg2 from dist-git @ 82c38c29114f ("gnupg-2.3.3-3", 2023-03-30), I find in "$HOME/rpmbuild/BUILD/gnupg-2.3.3/g10/gpg.c":
/* Options to override new security defaults. */
ARGPARSE_s_n (oAllowWeakKeySignatures, "allow-weak-key-signatures", "@"),
ARGPARSE_s_n (oAllowWeakDigestAlgos, "allow-weak-digest-algos", "@"),
ARGPARSE_s_n (oAllowOldCipherAlgos, "allow-old-cipher-algos", "@"),
ARGPARSE_s_s (oWeakDigest, "weak-digest","@"),
ARGPARSE_s_s (oVerifyOptions, "verify-options", "@"),
ARGPARSE_s_n (oEnableSpecialFilenames, "enable-special-filenames", "@"),
ARGPARSE_s_n (oNoRandomSeedFile, "no-random-seed-file", "@"),
ARGPARSE_s_n (oNoSigCache, "no-sig-cache", "@"),
ARGPARSE_s_n (oIgnoreTimeConflict, "ignore-time-conflict", "@"),
ARGPARSE_s_n (oIgnoreValidFrom, "ignore-valid-from", "@"),
ARGPARSE_s_n (oIgnoreCrcError, "ignore-crc-error", "@"),
ARGPARSE_s_n (oIgnoreMDCError, "ignore-mdc-error", "@"),
ARGPARSE_s_s (oDisableCipherAlgo, "disable-cipher-algo", "@"),
ARGPARSE_s_s (oDisablePubkeyAlgo, "disable-pubkey-algo", "@"),
ARGPARSE_s_s (oCipherAlgo, "cipher-algo", "@"),
ARGPARSE_s_s (oAEADAlgo, "aead-algo", "@"),
ARGPARSE_s_s (oDigestAlgo, "digest-algo", "@"),
ARGPARSE_s_s (oCertDigestAlgo, "cert-digest-algo", "@"),
... for future reference, if we need to relax more checks...
Thanks for your investigation. The version of gnupg2 has been downgraded from 2.3.3-3 to 2.3.3-2 in the latest RHEL9.3 nightly compose. And virt-builder works well as usual. There was some internal discussion and it seems as if this change will be reverted in gnupg2. We will still need to fix the libguestfs key, so let's keep this bug open. Issue migration from Bugzilla to Jira is in process at this time. This will be the last message in Jira copied from the Bugzilla bug. This BZ has been automatically migrated to the issues.redhat.com Red Hat Issue Tracker. All future work related to this report will be managed there. Due to differences in account names between systems, some fields were not replicated. Be sure to add yourself to Jira issue's "Watchers" field to continue receiving updates and add others to the "Need Info From" field to continue requesting information. To find the migrated issue, look in the "Links" section for a direct link to the new issue location. The issue key will have an icon of 2 footprints next to it, and begin with "RHEL-" followed by an integer. You can also find this issue by visiting https://issues.redhat.com/issues/?jql= and searching the "Bugzilla Bug" field for this BZ's number, e.g. a search like: "Bugzilla Bug" = 1234567 In the event you have trouble locating or viewing this issue, you can file an issue by sending mail to rh-issues. You can also visit https://access.redhat.com/articles/7032570 for general account information. |