[opensuse-project] What's the matter with the OBS PGP keys?
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 They are all obsolete. Just a sample: pub 1024D/BD6D129A 2008-01-22 [expired: 2010-04-01] uid Apache OBS Project <Apache@build.opensuse.org> pub 1024D/6B9D6523 2006-05-24 [expired: 2008-05-23] uid openSUSE Build Service <buildservice@opensuse.org> pub 1024D/9C800ACA 2000-10-19 [expired: 2010-05-05] uid SuSE Package Signing Key <build@suse.de> Worse, it is useless to try update from the key server network. And yes, there is a bugzilla. No reply in several days. - -- Cheers / Saludos, Carlos E. R. (from 11.2 x86_64 "Emerald" GM (Elessar)) -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.12 (GNU/Linux) Comment: Using GnuPG with SUSE - http://enigmail.mozdev.org/ iEYEARECAAYFAkxXHvYACgkQU92UU+smfQWwEQCggYkNIy2HUojr4Oxi4pBQbm3A 6AoAn1ddP6eCxV1EmvwO5qbNXrsQOr29 =C+Iz -----END PGP SIGNATURE----- -- To unsubscribe, e-mail: opensuse-project+unsubscribe@opensuse.org For additional commands, e-mail: opensuse-project+help@opensuse.org
Am Montag 02 August 2010 schrieb Carlos E. R.:
pub 1024D/6B9D6523 2006-05-24 [expired: 2008-05-23] uid openSUSE Build Service <buildservice@opensuse.org> Where is this key used? We stopped using one key to rule them all long ago.
pub 1024D/9C800ACA 2000-10-19 [expired: 2010-05-05] uid SuSE Package Signing Key <build@suse.de>
On my key server the key expires 2014 (wwwkeys.eu.pgp.net) Greetings, Stephan -- To unsubscribe, e-mail: opensuse-project+unsubscribe@opensuse.org For additional commands, e-mail: opensuse-project+help@opensuse.org
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 On 2010-08-03 10:12, Stephan Kulow wrote:
Am Montag 02 August 2010 schrieb Carlos E. R.:
pub 1024D/6B9D6523 2006-05-24 [expired: 2008-05-23] uid openSUSE Build Service <buildservice@opensuse.org> Where is this key used? We stopped using one key to rule them all long ago.
Those are the keys you find when trying to add a repo. I did the following on 2010-07-30 02:05 +++····································· I went to <http://download.opensuse.org/repositories/Apache:/Modules/openSUSE_11.3/>, downloaded "Apache:Modules.repo". Inside I read: [Apache_Modules] name=This project contains third-party modules for the Apache HTTP server. (openSUSE_11.3) type=rpm-md baseurl=http://download.opensuse.org/repositories/Apache:/Modules/openSUSE_11.3/ gpgcheck=1 gpgkey=http://download.opensuse.org/repositories/Apache:/Modules/openSUSE_11.3/repo... enabled=1 I then downloaded that gpgkey, and run: gpg --import repomd.xml.key Then I went to <http://download.opensuse.org/repositories/GNOME:/STABLE:/2.30/openSUSE_11.3/repodata/>, downloaded the key in there. Then, run "gpg --list-keys": pub 1024D/BD6D129A 2008-01-22 [expired: 2010-04-01] uid Apache OBS Project <Apache@build.opensuse.org> And the other might be this one: pub 1024D/6B9D6523 2006-05-24 [expired: 2008-05-23] uid openSUSE Build Service <buildservice@opensuse.org> ·····································++-
pub 1024D/9C800ACA 2000-10-19 [expired: 2010-05-05] uid SuSE Package Signing Key <build@suse.de>
On my key server the key expires 2014 (wwwkeys.eu.pgp.net)
But you have not uploaded it to the keyservers; seahorse finds it, but it is outdated. It you have renewed the expiration date, but not uploaded it to the network, it is as if you have done nothing. Seahorse is using hkp://pgp.mit.edu:11371 I tried with the other two keys mentioned above (seahorse) and I get the same result, expired. And the copy in the repo servers for 11.3 is the same one, thus expired. Seahorse is using: hkp://pgp.mit.edu:11371 ldap://keyserver.pgp.com I'm adding right now hkp://wwwkeys.eu.pgp.net. Now I sync keys. The apache and buildservice keys remain expired. Your build@suse.key has been renewed. So, "wwwkeys.eu.pgp.net" is not syncing to the rest. I have no idea about the files in the OBS server today. Ok, I'll wget the apache key again. cer@Elessar:~> l repomd.xml.* - -rw-r--r-- 1 cer users 987 2010-07-17 21:05 repomd.xml.key cer@Elessar:~> rm repomd.xml.* cer@Elessar:~> wget http://download.opensuse.org/repositories/Apache:/Modules/openSUSE_11.3/repo... - --2010-08-03 10:47:10-- http://download.opensuse.org/repositories/Apache:/Modules/openSUSE_11.3/repo... Resolving download.opensuse.org... 195.135.221.134 Connecting to download.opensuse.org|195.135.221.134|:80... connected. HTTP request sent, awaiting response... 200 OK Length: 987 [application/pgp-keys] Saving to: `repomd.xml.key' 100%[============================================================================================>] 987 --.-K/s in 0s 2010-08-03 10:47:10 (103 MB/s) - `repomd.xml.key' saved [987/987] cer@Elessar:~> l repomd.xml.* - -rw-r--r-- 1 cer users 987 2010-07-17 21:05 repomd.xml.key cer@Elessar:~> gpg --import repomd.xml.key gpg: key BD6D129A: "Apache OBS Project <Apache@build.opensuse.org>" not changed gpg: Total number processed: 1 gpg: unchanged: 1 Not changed. cer@Elessar:~> gpg --list-keys | tail ... pub 1024D/6B9D6523 2006-05-24 [expired: 2008-05-23] uid openSUSE Build Service <buildservice@opensuse.org> pub 1024D/BD6D129A 2008-01-22 [expired: 2010-04-01] uid Apache OBS Project <Apache@build.opensuse.org> Thus, the problem remains. - -- Cheers / Saludos, Carlos E. R. (from 11.2 x86_64 "Emerald" GM (Elessar)) -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.12 (GNU/Linux) Comment: Using GnuPG with SUSE - http://enigmail.mozdev.org/ iEYEARECAAYFAkxX2I4ACgkQU92UU+smfQVCdwCfdLvhv+jrnpzovd74HDh4XYM0 cTcAn1d/nuJHRlpNviPqYIq5tzxig4Ag =m+so -----END PGP SIGNATURE----- -- To unsubscribe, e-mail: opensuse-project+unsubscribe@opensuse.org For additional commands, e-mail: opensuse-project+help@opensuse.org
participants (2)
-
Carlos E. R.
-
Stephan Kulow