Details

    • Type: Bug
    • Status: Closed
    • Priority: Critical
    • Resolution: Done
    • Affects Version/s: None
    • Fix Version/s: 2017/08/02
    • Component/s: Build Automation, Packaging
    • Labels:
      None
    • Environment:

      Oracle Linux 7.2 Puppet Labs Repository

    • Template:
    • Story Points:
      2
    • Sprint:
      RE 2016-04-27

      Description

      Hello,
      we are using Puppet Community Edition on Oracle Linux 7.2 and we detected that the newer puppetlabs-release packe is not signed anymore. The older packages had been signed. The new package includes a new gpg-key, but is it right that they got a new one and that they are delivered in an unsigned package? We saw that with in the directories below:

      rpm -qlp puppetlabs-release-5-12.noarch.rpm
      /etc/pki/rpm-gpg/RPM-GPG-KEY-nightly-puppetlabs
      /etc/pki/rpm-gpg/RPM-GPG-KEY-puppetlabs
      /etc/yum.repos.d/puppetlabs.repo

      See example below:

      Old packege:

      Name : puppetlabs-release
      Version : 5
      Release : 11
      Architecture: noarch
      Install Date: (not installed)
      Group : System Environment/Base
      Size : 8533
      License : ASL 2.0
      Signature : RSA/SHA1, Tue 26 Aug 2014 07:26:19 PM CEST, Key ID 1054b7a24bd6ec30
      Source RPM : puppetlabs-release-5-11.src.rpm
      Build Date : Mon 25 Aug 2014 08:14:01 PM CEST
      Build Host : mills.delivery.puppetlabs.net
      Relocations : (not relocatable)
      URL : http://yum.puppetlabs.com
      Summary : Configuration for yum.puppetlabs.com
      Description :
      This package contains the yum.puppetlabs.com repository
      GPG key as well as configuration for a yum client.

      New packege:
      Name : puppetlabs-release
      Version : 5
      Release : 12
      Architecture: noarch
      Install Date: (not installed)
      Group : System Environment/Base
      Size : 11542
      License : ASL 2.0
      Signature : (none)
      Source RPM : puppetlabs-release-5-12.src.rpm
      Build Date : Tue 12 Apr 2016 08:01:18 PM CEST
      Build Host : loch.delivery.puppetlabs.net
      Relocations : (not relocatable)
      URL : http://yum.puppetlabs.com
      Summary : Configuration for yum.puppetlabs.com
      Description :
      This package contains the yum.puppetlabs.com repository
      GPG key as well as configuration for a yum client.

      Why is the new package not signed?

        Attachments

          Activity

            People

            • Assignee:
              pndh-dci DCI
              Reporter:
              pndh-dci DCI
            • Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:

                Zendesk Support