Hello, 
  The RPMs and SRPMs on the ftp site of the 1.0 release seem to have been
signed with a different (inaccessible) key with KeyID: 113E6CFC (GPG). The
signing key for (S)RPMS and advisories according to OpenPKG security page
must be 63C4CB9F (GPG). 

Example (for SRPM and RPM, "rpm" is from the openpkg bootstrap on RH 6.x):

$ rpm --checksig txt2man-1.4.3-1.0.0.src.rpm
txt2man-1.4.3-1.0.0.src.rpm: md5 (GPG) OK (MISSING KEYS: GPG#113E6CFC)

$ rpm --checksig a2ps-4.13-1.0.0.ix86-freebsd4.4-cw.rpm 
a2ps-4.13-1.0.0.ix86-freebsd4.4-cw.rpm: md5 (GPG) OK (MISSING KEYS: GPG#113E6CFC)

[ source: ftp://ftp.openpkg.org:21/release/1.0/{SRC,BIN}/ ]

Regards.
                                                                -Ravindra
-- 
-Key:finger [EMAIL PROTECTED]| See header X-GPG-FP for fingerprint-

Attachment: msg00154/pgp00000.pgp
Description: PGP signature

Reply via email to