Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 530598 - yum not downloading gpgkey from http:// url in "GPG key URL"
yum not downloading gpgkey from http:// url in "GPG key URL"
Status: CLOSED NOTABUG
Product: Spacewalk
Classification: Community
Component: WebUI (Show other bugs)
0.6
x86_64 Linux
low Severity medium
: ---
: ---
Assigned To: Michael Mráka
Red Hat Satellite QA List
:
Depends On:
Blocks: space13
  Show dependency treegraph
 
Reported: 2009-10-23 12:49 EDT by Josh Mullis
Modified: 2011-01-28 09:53 EST (History)
3 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2011-01-28 09:53:51 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Josh Mullis 2009-10-23 12:49:43 EDT
Description of problem:

In spacewalk channel properties, if a "file://" url is specified in the "GPG key URL" field, yum on the client automatically imports the key.

However if an "http://" url is specified in the field, yum does not automatically import.




Version-Release number of selected component (if applicable):

RHEL v5.2
Spacewalk v0.6.4-1




How reproducible:
Steps to Reproduce:
1. Remove your custom gpgkey from rpm db
2. Enter a valid http:// url (to a gpgkey that your rpms are signed with) in the "GPG key URL" field of the channel (containing your signed rpms) properties.

3. On a client registered with spacewalk and is entitled to this channel, attempt to download a package from the channel in question.



Actual results:
Public key for <package_name> is not installed




Expected results:

yum automatically downloads gpgkey from url.





Additional info:

This works if you have a /etc/yum.repo/reponame.repo with a...

"gpgkey=http://path_to_key"  in the file.





Many Thanks!
Comment 1 Josh Mullis 2009-10-23 12:54:36 EDT
A custom gpgkey is what I'm using, but you can try this with any gpg key that is linked to any repository.

I tried it with linuxha gpgkey, with no luck.
Comment 2 Jan Pazdziora 2010-11-19 11:04:51 EST
Mass-moving to space13.
Comment 3 Michael Mráka 2011-01-28 09:53:51 EST
Rhnplugin don't allow to import automatically other keys than file://etc/pki/rpm-gpg/* for security reason - checking packages downloaded over the net with key downloaded from the same source can be very easily man-in-the-middle attacked.

You have to create an rpm with custom keys similar to redhat-release, fedora-release or epel-release.

Note You need to log in before you can comment on or make changes to this bug.