Hi All,

We used to sign using SHA1 algorithm which is deprecated and the latest 
packages are signed using SHA512. In-order to resolve this issue, the 
corresponding public key needs to be imported before yum update. Kindly run the 
following command to import the public key. 

rpm --import http://linux.dell.com/repo/pgp_pubkeys/0x1285491434D8786F.asc

Let us know if you face any challenges.

Regards,
Chandra 
----------------------------------------------------------------------

Message: 1
Date: Thu, 21 Jun 2018 12:33:24 -0700
From: Kilian Cavalotti <kilian.cavalotti.w...@gmail.com>
To: linux-powere...@lists.us.dell.com
Subject: [Linux-PowerEdge] RPM repo GPG key changed?
Message-ID:
        <CAJz=vjg8dowmszzjcekz_kj+wbqx3pfjwna517p9lirp4fa...@mail.gmail.com>
Content-Type: text/plain; charset="UTF-8"

Hi,

Did the RPM repository GPG keys change somehow?

Trying to update srvadmin packages today leads to the following error:

-------------------------
Retrieving key from http://linux.dell.com/repo/hardware/dsu/public.key


The GPG keys listed for the "dell-system-update_dependent" repository are 
already installed but they are not correct for this package.
Check that the correct key URLs are configured for this repository.


Failing package is: srvadmin-omilcore-9.1.0-3013.13047.el7.x86_64
GPG Keys are configured as: http://linux.dell.com/repo/hardware/dsu/public.key
-------------------------

FWIW, the repository configuration didn't change on that host, and it has been 
working fine for months.

Cheers,
--
Kilian



------------------------------

Message: 2
Date: Thu, 21 Jun 2018 13:37:37 -0600
From: Erinn Looney-Triggs <erinn.looneytri...@gmail.com>
To: linux-poweredge@dell.com
Subject: Re: [Linux-PowerEdge] RPM repo GPG key changed?
Message-ID: <aae8c0ef-7594-abf8-7ea3-4900cb199...@gmail.com>
Content-Type: text/plain; charset=utf-8

Same here just to confirm your findings.


On 06/21/2018 01:33 PM, Kilian Cavalotti wrote:
> Hi,
>
> Did the RPM repository GPG keys change somehow?
>
> Trying to update srvadmin packages today leads to the following error:
>
> -------------------------
> Retrieving key from http://linux.dell.com/repo/hardware/dsu/public.key
>
>
> The GPG keys listed for the "dell-system-update_dependent" repository
> are already installed but they are not correct for this package.
> Check that the correct key URLs are configured for this repository.
>
>
> Failing package is: srvadmin-omilcore-9.1.0-3013.13047.el7.x86_64
> GPG Keys are configured as: http://linux.dell.com/repo/hardware/dsu/public.key
> -------------------------
>
> FWIW, the repository configuration didn't change on that host, and it
> has been working fine for months.
>
> Cheers,



------------------------------

Message: 3
Date: Thu, 21 Jun 2018 22:45:07 +0300
From: Anssi Johansson <cen...@miuku.net>
To: linux-poweredge@dell.com
Subject: Re: [Linux-PowerEdge] RPM repo GPG key changed?
Message-ID: <34a6a06f-f383-0e33-8d1e-98a60af29...@miuku.net>
Content-Type: text/plain; charset=utf-8; format=flowed

Kilian Cavalotti kirjoitti 21.6.2018 klo 22.33:
> Hi,
> 
> Did the RPM repository GPG keys change somehow?
> 
> Trying to update srvadmin packages today leads to the following error:
> 
> -------------------------
> Retrieving key from http://linux.dell.com/repo/hardware/dsu/public.key
> 
> 
> The GPG keys listed for the "dell-system-update_dependent" repository
> are already installed but they are not correct for this package.
> Check that the correct key URLs are configured for this repository.
> 
> 
> Failing package is: srvadmin-omilcore-9.1.0-3013.13047.el7.x86_64
> GPG Keys are configured as: http://linux.dell.com/repo/hardware/dsu/public.key
> -------------------------
> 
> FWIW, the repository configuration didn't change on that host, and it
> has been working fine for months.

Yes, something has definitely changed.

# yum update
...
Dependencies Resolved

=============================================================================================================
  Package                     Arch             Version 
      Repository                 Size
=============================================================================================================
Updating:
  srvadmin-omacs              x86_64           9.1.0-3013.13047.el7 
      dell-omsa-indep           2.7 M
  srvadmin-omilcore           x86_64           9.1.0-3013.13047.el7 
      dell-omsa-indep            37 k

Transaction Summary
=============================================================================================================
Upgrade  2 Packages

Total size: 2.7 M
Is this ok [y/d/N]: y
Downloading packages:
warning: 
/var/cache/yum/x86_64/7/dell-omsa-indep/packages/srvadmin-omilcore-9.1.0-3013.13047.el7.x86_64.rpm:
 
Header V4 RSA/SHA512 Signature, key ID 34d8786f: NOKEY
Retrieving key from 
http://linux.dell.com/repo/hardware/latest/RPM-GPG-KEY-dell


GPG key retrieval failed: [Errno 14] HTTP Error 404 - Not Found



------------------------------

Message: 4
Date: Thu, 21 Jun 2018 22:54:19 +0300
From: Anssi Johansson <cen...@miuku.net>
To: linux-poweredge@dell.com
Subject: Re: [Linux-PowerEdge] RPM repo GPG key changed?
Message-ID: <b7fed761-9ed1-b74a-4354-e33901815...@miuku.net>
Content-Type: text/plain; charset=utf-8; format=flowed

Kilian Cavalotti kirjoitti 21.6.2018 klo 22.33:
> Hi,
> 
> Did the RPM repository GPG keys change somehow?

Further info:

Current installed package:

# rpm -qi srvadmin-omilcore
Name        : srvadmin-omilcore
Version     : 9.1.0
Release     : 2757.12163.el7
Architecture: x86_64
Install Date: Tue 26 Dec 2017 10:26:04 PM EET
Group       : System/Configuration/Hardware
Size        : 85659
License     : Dell Proprietary
Signature   : DSA/SHA1, Sun 22 Oct 2017 06:16:27 PM EEST, Key ID 
ca77951d23b66a9d
Source RPM  : srvadmin-omilcore-9.1.0-2757.12163.el7.src.rpm
Build Date  : Sun 22 Oct 2017 06:04:38 PM EEST
Build Host  : bsmvr70pbl01.blr.amer.dell.com
Relocations : (not relocatable)
Vendor      : Dell Inc
URL         : http://support.dell.com
Summary     : Server Administrator Install Core, 9.1.0

Package that was downloaded:

# rpm -qip srvadmin-omilcore-9.1.0-3013.13047.el7.x86_64.rpm
warning: srvadmin-omilcore-9.1.0-3013.13047.el7.x86_64.rpm: Header V4 
RSA/SHA512 Signature, key ID 34d8786f: NOKEY
Name        : srvadmin-omilcore
Version     : 9.1.0
Release     : 3013.13047.el7
Architecture: x86_64
Install Date: (not installed)
Group       : System/Configuration/Hardware
Size        : 85659
License     : Dell Proprietary
Signature   : RSA/SHA512, Wed 30 May 2018 10:41:04 PM EEST, Key ID 
1285491434d8786f
Source RPM  : srvadmin-omilcore-9.1.0-3013.13047.el7.src.rpm
Build Date  : Wed 30 May 2018 10:31:15 PM EEST
Build Host  : bsmvr70pbl01.blr.amer.dell.com
Relocations : (not relocatable)
Vendor      : Dell Inc
URL         : http://support.dell.com
Summary     : Server Administrator Install Core, 9.1.0.2

Note the Signature line, different keys are being used. 1285491434d8786f 
is a Dell key, but looks like it's primarily used for signing 
Debian/Ubuntu packages. If this change was intentional, I'd say it 
wasn't properly communicated.



------------------------------

Subject: Digest Footer

_______________________________________________
Linux-PowerEdge mailing list
Linux-PowerEdge@dell.com
https://lists.us.dell.com/mailman/listinfo/linux-poweredge

------------------------------

End of Linux-PowerEdge Digest, Vol 169, Issue 11
************************************************

_______________________________________________
Linux-PowerEdge mailing list
Linux-PowerEdge@dell.com
https://lists.us.dell.com/mailman/listinfo/linux-poweredge

Reply via email to