new key for security devel project
![](https://seccdn.libravatar.org/avatar/bff0c215e01f23fcee6fe49e65fae458.jpg?s=120&d=mm&r=g)
Hi folks, We will switch the "security" development project to a 4096bit RSA key today. Ciao, Marcus -- Marcus Meissner (he/him), Distinguished Engineer / Senior Project Manager Security SUSE Software Solutions Germany GmbH, Frankenstrasse 146, 90461 Nuernberg, Germany GF: Ivo Totev, Andrew McDonald, Werner Knoblich, HRB 36809, AG Nuernberg
![](https://seccdn.libravatar.org/avatar/bff0c215e01f23fcee6fe49e65fae458.jpg?s=120&d=mm&r=g)
On Mon, Sep 23, 2024 at 02:16:49PM +0200, Marcus Meissner wrote:
Hi folks,
We will switch the "security" development project to a 4096bit RSA key today.
New key fingerprint: Type : GPG public key User ID : security OBS Project <security@build.opensuse.org> Algorithm : rsa Key size : 4096 Expires : 2026-12-02 13:27:55 Fingerprint : f9fa 0223 b56b 116c 3637 37ef 5da5 7bdd 6dd7 85ca Ciao, Marcus
![](https://seccdn.libravatar.org/avatar/1a9b09438746699c6ec5a6cd4eb9f44c.jpg?s=120&d=mm&r=g)
Hi Marcus, Thank for update the key and maintaining the security devel project! I had a signature validation failed. It seems like the validation failed for repomd fils in security/SLE_12_SP5/repodata/ due to the key is created after the project's build. gpg --verify repomd.xml.asc repomd.xml gpg: Signature made Mon Sep 23 12:21:17 2024 UTC using RSA key ID 6DD785CA gpg: public key 6DD785CA is 398 seconds newer than the signature gpg: Can't check signature: Time conflict I am wondering if we can trigger a rebuild of the SLE_12_SP5 security project to have the repomd rebuild? Thank you so much for your help! Best, John
![](https://seccdn.libravatar.org/avatar/3ec791b178b445bf91ca15a5ffb361b9.jpg?s=120&d=mm&r=g)
On Wed, Sep 25, 2024 at 06:26:47PM -0000, John Wang via openSUSE Factory wrote:
I am wondering if we can trigger a rebuild of the SLE_12_SP5 security project to have the repomd rebuild?
I did it, might take a bit to build Johannes -- GPG Key EE16 6BCE AD56 E034 BFB3 3ADD 7BF7 29D5 E7C8 1FA0 Subkey fingerprint: 250F 43F5 F7CE 6F1E 9C59 4F95 BC27 DD9D 2CC4 FD66 SUSE Software Solutions Germany GmbH, Frankenstraße 146, 90461 Nürnberg, Germany Geschäftsführer: Ivo Totev, Andrew McDonald, Werner Knoblich (HRB 36809, AG Nürnberg)
![](https://seccdn.libravatar.org/avatar/a58efdcdbe0b6139a9f968d07bd449ad.jpg?s=120&d=mm&r=g)
Hi Johannes, Can you please confirm if the rebuild for the SLE_12_SP5 security-tools project has been completed? Thank You, Eli
![](https://seccdn.libravatar.org/avatar/3ec791b178b445bf91ca15a5ffb361b9.jpg?s=120&d=mm&r=g)
Hi, On Fri, Sep 27, 2024 at 01:53:40AM -0000, Eli Atzaba via openSUSE Factory wrote:
Can you please confirm if the rebuild for the SLE_12_SP5 security-tools project has been completed?
By now it for sure is done. Do you still have issues? Johannes -- GPG Key EE16 6BCE AD56 E034 BFB3 3ADD 7BF7 29D5 E7C8 1FA0 Subkey fingerprint: 250F 43F5 F7CE 6F1E 9C59 4F95 BC27 DD9D 2CC4 FD66 SUSE Software Solutions Germany GmbH, Frankenstraße 146, 90461 Nürnberg, Germany Geschäftsführer: Ivo Totev, Andrew McDonald, Werner Knoblich (HRB 36809, AG Nürnberg)
![](https://seccdn.libravatar.org/avatar/1a9b09438746699c6ec5a6cd4eb9f44c.jpg?s=120&d=mm&r=g)
Hi Johannes, Thank you so much for the rebuild! If possible, would you mind sharing how long this process normally takes? Thank you again for maintaining Open SUSE! Best, John
participants (4)
-
Eli Atzaba
-
Johannes Segitz
-
John Wang
-
Marcus Meissner