[Bug 1176818] New: Wrong public keys in openSUSE-build-key for verifying container image signatures
https://bugzilla.suse.com/show_bug.cgi?id=1176818 Bug ID: 1176818 Summary: Wrong public keys in openSUSE-build-key for verifying container image signatures Classification: openSUSE Product: openSUSE Tumbleweed Version: Current Hardware: Other OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Basesystem Assignee: meissner@suse.com Reporter: rhafer@suse.com QA Contact: qa-bugs@suse.de CC: sgrunert@suse.com Found By: --- Blocker: --- The openSUSE-build-keys package contains /usr/lib/rpm/gnupg/keys/opensuse-container-key.asc and /usr/lib/rpm/gnupg/keys/suse-container-key.asc which symlink to the "openSUSE Project Signing Key <opensuse@opensuse.org>" and "SuSE Package Signing Key <build@suse.de>" but apparently the images we provide on registry.opensuse.org are signed by some other key. When enabling signature verification for "registry.opensuse.org" using the key "/usr/lib/rpm/gnupg/keys/opensuse-container-key.asc" all images fail to verify because the images are signed with a different key. Looking into the signatures, which are fetched from "https://registry.opensuse.org/sigstore/" it seem the images are signed by a key with the ID "D754694F9AB48CE9". The key in /usr/lib/rpm/gnupg/keys/opensuse-container-key.asc however AFAICS is: "B88B2FD43DBDC284". So something is wrong here. -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1176818 https://bugzilla.suse.com/show_bug.cgi?id=1176818#c1 --- Comment #1 from Marcus Meissner <meissner@suse.com> --- Yes, I so far thought we use the build@suse.de key also for containers, but the container key is different. I submitted suse-build-key updates to QA. i did not yet do openSUSE-build-key, will do soon. -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1176818 https://bugzilla.suse.com/show_bug.cgi?id=1176818#c2 --- Comment #2 from OBSbugzilla Bot <bwiedemann+obsbugzillabot@suse.com> --- This is an autogenerated message for OBS integration: This bug (1176818) was mentioned in https://build.opensuse.org/request/show/836127 Factory / openSUSE-build-key -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1176818 https://bugzilla.suse.com/show_bug.cgi?id=1176818#c3 --- Comment #3 from Ralf Haferkamp <rhafer@suse.com> --- (In reply to Marcus Meissner from comment #1)
i did not yet do openSUSE-build-key, will do soon.
Cool, thanks. And indeed using the keys from the above SR I am able to verify images from registry.opensuse.org. -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1176818 https://bugzilla.suse.com/show_bug.cgi?id=1176818#c4 Dirk Mueller <dmueller@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Status|NEW |RESOLVED Resolution|--- |FIXED --- Comment #4 from Dirk Mueller <dmueller@suse.com> --- . -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com