Bug 2464087 - DNF for verifying repositories and RPM for verifying packages use different OpenPGP database
Summary: DNF for verifying repositories and RPM for verifying packages use different O...
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Fedora
Classification: Fedora
Component: dnf
Version: 44
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
Assignee: rpm-software-management
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-04-30 11:14 UTC by Kamil Páral (Red Hat)
Modified: 2026-04-30 11:45 UTC (History)
8 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-04-30 11:28:47 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)

Description Kamil Páral (Red Hat) 2026-04-30 11:14:52 UTC
Description of problem:
When I add a GPG key through RPM, DNF doesn't see it, and vice versa. Discovered on Fedora 44 with this extra repo present:

$ cat /etc/yum.repos.d/cursor.repo 
[cursor]
name=Cursor
baseurl=https://downloads.cursor.com/yumrepo
enabled=1
gpgcheck=1
gpgkey=https://downloads.cursor.com/keys/anysphere.asc
repo_gpgcheck=1


=== Machine 1: a key added through `rpm --import` is not seen by DNF ===

$ rpmkeys -l
36f612dcf27f7d1a48a835e4dbfcf71c6d9f90a6 Fedora (44) <fedora-44-primary> public key

$ sudo rpm --import 'https://downloads.cursor.com/keys/anysphere.asc'

$ rpmkeys -l
380ff4bcdc34a4bd92a3565342a1772e62e492d6 Anysphere Inc <security> public key
36f612dcf27f7d1a48a835e4dbfcf71c6d9f90a6 Fedora (44) <fedora-44-primary> public key

$ sudo dnf update
Updating and loading repositories:
 Cursor                                                                                             100% |   6.7 KiB/s |   4.3 KiB |  00m01s
>>> repomd.xml GPG signature verification error: Signing key not found
 https://downloads.cursor.com/keys/anysphere.asc                                                    100% |   4.0 KiB/s |   1.6 KiB |  00m00s
Importing OpenPGP key 0x62E492D6:
 UserID     : "Anysphere Inc <security>"
 Fingerprint: 380FF4BCDC34A4BD92A3565342A1772E62E492D6
 From       : https://downloads.cursor.com/keys/anysphere.asc
Is this ok [y/N]:


=== Machine 2: a key added through DNF is not seen by rpmkeys ===

$ rpmkeys -l
36f612dcf27f7d1a48a835e4dbfcf71c6d9f90a6 Fedora (44) <fedora-44-primary> public key

$ sudo dnf update
Updating and loading repositories:
 Cursor                                                                                             100% |   4.8 KiB/s |   4.3 KiB |  00m01s
>>> repomd.xml GPG signature verification error: Signing key not found
 https://downloads.cursor.com/keys/anysphere.asc                                                    100% |   8.7 KiB/s |   1.6 KiB |  00m00s
Importing OpenPGP key 0x62E492D6:
 UserID     : "Anysphere Inc <security>"
 Fingerprint: 380FF4BCDC34A4BD92A3565342A1772E62E492D6
 From       : https://downloads.cursor.com/keys/anysphere.asc
Is this ok [y/N]: y
The key was successfully imported.
 Cursor                                                                                             100% | 164.6 KiB/s | 174.5 KiB |  00m01s
Repositories loaded.
Nothing to do.

$ rpmkeys -l
36f612dcf27f7d1a48a835e4dbfcf71c6d9f90a6 Fedora (44) <fedora-44-primary> public key



Version-Release number of selected component (if applicable):
dnf5-5.4.2.0-1.fc44.x86_64
rpm-6.0.1-2.fc44.x86_64


How reproducible:
always

Steps to Reproduce:
1. follow the description above

Actual results:
DNF and RPM don't share imported GPG keys database

Expected results:
DNF and RPM share imported GPG keys database

Comment 1 Petr Pisar 2026-04-30 11:28:47 UTC
Do you use DNF4 or DNF5?

Nonetheless, you observation is correct: For verifying repositories (repo_gpgcheck=1) DNF(5) uses it own keyring.
Contrary, for verifying packages (gpgcheck=1) DNF(5) uses RPM keyring.

That's nothing new and I believe there are good reasons for it. One of them is that a nonsuperuser might want to search a repository with repo_gpgcheck=1 set. Such a user, naturally, does not have write access to RPM keyring. If DNF(5) only used RPM keyring, this use would be impossible.

Comment 2 Kamil Páral (Red Hat) 2026-04-30 11:45:52 UTC
(In reply to Petr Pisar from comment #1)
> Do you use DNF4 or DNF5?

DNF5.

> Nonetheless, you observation is correct: For verifying repositories
> (repo_gpgcheck=1) DNF(5) uses it own keyring.
> Contrary, for verifying packages (gpgcheck=1) DNF(5) uses RPM keyring.

Hmm, OK. We're trying to figure out bug 2463519 and this confused me a lot - I believed it might play a part in those issues.


Note You need to log in before you can comment on or make changes to this bug.