On viernes, 25 de junio de 2021 14:58:03 (CEST) Simon Avery wrote:
No - the error happened today during the major update.
I can't reproduce your issue. For me the package installs without that warning. Is there anything particular about that system? The complain looks like a problem with the keystore. Can anyone reproduce that problem?
Additionally, when I try to register or re-register clients (Centos 7, for example), it fails and salt/minion logs this, which feels related;
Can I add this key manually?
I think your problem is not the GPG key, but the SSL certificate installed at the proxy the Proxy. Did you follow the instructions to deploy the proxy, or are you using your own SSL certificates?
2021-06-25 13:43:32,162 [salt.loaded.int.module.cmdmod:842 ][ERROR ][10644] retcode: 1 2021-06-25 13:43:32,162 [salt.state :323 ][ERROR ][10644] {u'pid': 10737, u'retcode': 1, u'stderr': u'curl: (60) Peer\'s Certificate issuer is not recognized.\nMore details here: http://curl.haxx.se/docs/sslcerts.html\n\ncurl<http://curl.haxx.se/docs/ssl certs.html/n/ncurl> performs SSL certificate verification by default, using a "bundle"\n of Certificate Authority (CA) public keys (CA certs). If the default\n bundle file isn\'t adequate, you can specify an alternate file\n using the --cacert option.\nIf this HTTPS server uses a certificate signed by a CA represented in\n the bundle, the certificate verification probably failed due to a\n problem with the certificate (it might be expired, or the name might\n not match the domain name in the URL).\nIf you\'d like to turn off curl\'s verification of the certificate, use\n the -k (or --insecure) option.\nerror: https://ata-oxy-uyuni01.atass.com/pub/res-gpg-pubkey-0182b964.key: import read failed(2).', u'stdout': u''} 2021-06-25 13:43:32,590 [salt.loaded.int.module.cmdmod:836 ][ERROR ][10644] Command 'rpm' failed with return code: 1 2021-06-25 13:43:32,590 [salt.loaded.int.module.cmdmod:840 ][ERROR ][10644] stderr: curl: (60) Peer's Certificate issuer is not recognized. More details here: http://curl.haxx.se/docs/sslcerts.html
curl performs SSL certificate verification by default, using a "bundle" of Certificate Authority (CA) public keys (CA certs). If the default bundle file isn't adequate, you can specify an alternate file using the --cacert option. If this HTTPS server uses a certificate signed by a CA represented in the bundle, the certificate verification probably failed due to a problem with the certificate (it might be expired, or the name might not match the domain name in the URL). If you'd like to turn off curl's verification of the certificate, use the -k (or --insecure) option. error: https://ata-oxy-uyuni01.atass.com/pub/sle12-gpg-pubkey-39db7c82.key: import read failed(2). 2021-06-25 13:43:32,591 [salt.loaded.int.module.cmdmod:842 ][ERROR ][10644] retcode: 1 2021-06-25 13:43:32,591 [salt.state :323 ][ERROR ][10644] {u'pid': 10775, u'retcode': 1, u'stderr': u'curl: (60) Peer\'s Certificate issuer is not recognized.\nMore details here: http://curl.haxx.se/docs/sslcerts.html\n\ncurl<http://curl.haxx.se/docs/ssl certs.html/n/ncurl> performs SSL certificate verification by default, using a "bundle"\n of Certificate Authority (CA) public keys (CA certs). If the default\n bundle file isn\'t adequate, you can specify an alternate file\n using the --cacert option.\nIf this HTTPS server uses a certificate signed by a CA represented in\n the bundle, the certificate verification probably failed due to a\n problem with the certificate (it might be expired, or the name might\n not match the domain name in the URL).\nIf you\'d like to turn off curl\'s verification of the certificate, use\n the -k (or --insecure) option.\nerror: https://ata-oxy-uyuni01.atass.com/pub/sle12-gpg-pubkey-39db7c82.key: import read failed(2).', u'stdout': u''}
-----Original Message----- From: Julio Gonzalez
Sent: 25 June 2021 11:52 To: uyuni-users@opensuse.org; users@lists.uyuni-project.org; Simon Avery Subject: [EXTERNAL EMAIL] Re: Unable to restart Uyuni following Uyuni upgrade 2021-06 On viernes, 25 de junio de 2021 11:28:06 (CEST) Simon Avery wrote: I rolled right back from yesterday to a 2021-05 state, so none of yesterday's attempts affected it - so please disregard any of that.
So the error happened yesterday, and not with the migration you performed today after the rollback, right?
I an confirm that I could not reproduce this problem. In my case uyuni-build- keys installs without that warning.
This error was at the end of ` /usr/lib/susemanager/bin/server-migrator.sh`
Once rebooted, I then ran ` /usr/lib/susemanager/bin/pg-migrate-12-to-13.sh`
which completed normally, and Uyuni started up.
S
-----Original Message----- From: Julio Gonzalez
Sent: 25 June 2021 10:26 To: uyuni-users@opensuse.org; users@lists.uyuni-project.org; Simon Avery Subject: [EXTERNAL EMAIL] Re: Unable to restart Uyuni following Uyuni upgrade 2021-06 On viernes, 25 de junio de 2021 11:02:20 (CEST) Simon Avery wrote:
At the end of the migration script, it showed this, prompting me to review scrollback.
Migration went wrong. Please fix the issues and try again.