Fedora Account System
Red Hat Associate
Red Hat Customer
Description of problem: When I add a GPG key through RPM, DNF doesn't see it, and vice versa. Discovered on Fedora 44 with this extra repo present: $ cat /etc/yum.repos.d/cursor.repo [cursor] name=Cursor baseurl=https://downloads.cursor.com/yumrepo enabled=1 gpgcheck=1 gpgkey=https://downloads.cursor.com/keys/anysphere.asc repo_gpgcheck=1 === Machine 1: a key added through `rpm --import` is not seen by DNF === $ rpmkeys -l 36f612dcf27f7d1a48a835e4dbfcf71c6d9f90a6 Fedora (44) <fedora-44-primary> public key $ sudo rpm --import 'https://downloads.cursor.com/keys/anysphere.asc' $ rpmkeys -l 380ff4bcdc34a4bd92a3565342a1772e62e492d6 Anysphere Inc <security> public key 36f612dcf27f7d1a48a835e4dbfcf71c6d9f90a6 Fedora (44) <fedora-44-primary> public key $ sudo dnf update Updating and loading repositories: Cursor 100% | 6.7 KiB/s | 4.3 KiB | 00m01s >>> repomd.xml GPG signature verification error: Signing key not found https://downloads.cursor.com/keys/anysphere.asc 100% | 4.0 KiB/s | 1.6 KiB | 00m00s Importing OpenPGP key 0x62E492D6: UserID : "Anysphere Inc <security>" Fingerprint: 380FF4BCDC34A4BD92A3565342A1772E62E492D6 From : https://downloads.cursor.com/keys/anysphere.asc Is this ok [y/N]: === Machine 2: a key added through DNF is not seen by rpmkeys === $ rpmkeys -l 36f612dcf27f7d1a48a835e4dbfcf71c6d9f90a6 Fedora (44) <fedora-44-primary> public key $ sudo dnf update Updating and loading repositories: Cursor 100% | 4.8 KiB/s | 4.3 KiB | 00m01s >>> repomd.xml GPG signature verification error: Signing key not found https://downloads.cursor.com/keys/anysphere.asc 100% | 8.7 KiB/s | 1.6 KiB | 00m00s Importing OpenPGP key 0x62E492D6: UserID : "Anysphere Inc <security>" Fingerprint: 380FF4BCDC34A4BD92A3565342A1772E62E492D6 From : https://downloads.cursor.com/keys/anysphere.asc Is this ok [y/N]: y The key was successfully imported. Cursor 100% | 164.6 KiB/s | 174.5 KiB | 00m01s Repositories loaded. Nothing to do. $ rpmkeys -l 36f612dcf27f7d1a48a835e4dbfcf71c6d9f90a6 Fedora (44) <fedora-44-primary> public key Version-Release number of selected component (if applicable): dnf5-5.4.2.0-1.fc44.x86_64 rpm-6.0.1-2.fc44.x86_64 How reproducible: always Steps to Reproduce: 1. follow the description above Actual results: DNF and RPM don't share imported GPG keys database Expected results: DNF and RPM share imported GPG keys database
Do you use DNF4 or DNF5? Nonetheless, you observation is correct: For verifying repositories (repo_gpgcheck=1) DNF(5) uses it own keyring. Contrary, for verifying packages (gpgcheck=1) DNF(5) uses RPM keyring. That's nothing new and I believe there are good reasons for it. One of them is that a nonsuperuser might want to search a repository with repo_gpgcheck=1 set. Such a user, naturally, does not have write access to RPM keyring. If DNF(5) only used RPM keyring, this use would be impossible.
(In reply to Petr Pisar from comment #1) > Do you use DNF4 or DNF5? DNF5. > Nonetheless, you observation is correct: For verifying repositories > (repo_gpgcheck=1) DNF(5) uses it own keyring. > Contrary, for verifying packages (gpgcheck=1) DNF(5) uses RPM keyring. Hmm, OK. We're trying to figure out bug 2463519 and this confused me a lot - I believed it might play a part in those issues.