#1881 Bad signature on eclipse-nls-da in F11 updates repo
Closed: Invalid None Opened 14 years ago by pghmcfc.

It's been like this for a while now so I guess it's not been reported before:
{{{
$ wget http://download.fedora.redhat.com/pub/fedora/linux/updates/11/x86_64/eclipse-nls-da-3.4.0.v20090423085802-1.fc11.noarch.rpm
--2009-05-26 07:41:29-- http://download.fedora.redhat.com/pub/fedora/linux/updates/11/x86_64/eclipse-nls-da-3.4.0.v20090423085802-1.fc11.noarch.rpm
Resolving download.fedora.redhat.com... 209.132.176.221, 209.132.176.20, 209.132.176.220
Connecting to download.fedora.redhat.com|209.132.176.221|:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 2013409 (1.9M) [application/x-rpm]
Saving to: `eclipse-nls-da-3.4.0.v20090423085802-1.fc11.noarch.rpm'

100%[================================================================================================>] 2,013,409 161K/s in 10s

2009-05-26 07:41:40 (191 KB/s) - `eclipse-nls-da-3.4.0.v20090423085802-1.fc11.noarch.rpm' saved [2013409/2013409]

$ rpm -p --checksig eclipse-nls-da-3.4.0.v20090423085802-1.fc11.noarch.rpm
eclipse-nls-da-3.4.0.v20090423085802-1.fc11.noarch.rpm: RSA sha1 (md5) pgp md5 NOT OK
}}}

By way of comparison, the same thing for eclipse-nls-de:
{{{
$ wget http://download.fedora.redhat.com/pub/fedora/linux/updates/11/x86_64/eclipse-nls-de-3.4.0.v20090423085802-1.fc11.noarch.rpm
--2009-05-26 07:42:13-- http://download.fedora.redhat.com/pub/fedora/linux/updates/11/x86_64/eclipse-nls-de-3.4.0.v20090423085802-1.fc11.noarch.rpm
Resolving download.fedora.redhat.com... 209.132.176.220, 209.132.176.221, 209.132.176.20
Connecting to download.fedora.redhat.com|209.132.176.220|:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 2389745 (2.3M) [application/x-rpm]
Saving to: `eclipse-nls-de-3.4.0.v20090423085802-1.fc11.noarch.rpm'

100%[================================================================================================>] 2,389,745 274K/s in 9.5s

2009-05-26 07:42:23 (245 KB/s) - `eclipse-nls-de-3.4.0.v20090423085802-1.fc11.noarch.rpm' saved [2389745/2389745]

$ rpm -p --checksig eclipse-nls-de-3.4.0.v20090423085802-1.fc11.noarch.rpmeclipse-nls-de-3.4.0.v20090423085802-1.fc11.noarch.rpm: rsa sha1 (md5) pgp md5 OK
}}}


Works for me.

{{{
[notting@nostromo: ~]$ wget http://download.fedora.redhat.com/pub/fedora/linux/updates/11/x86_64/eclipse-nls-da-3.4.0.v20090423085802-1.fc11.noarch.rpm
--2009-05-26 12:13:12-- http://download.fedora.redhat.com/pub/fedora/linux/updates/11/x86_64/eclipse-nls-da-3.4.0.v20090423085802-1.fc11.noarch.rpm
Resolving download.fedora.redhat.com... 209.132.176.220, 209.132.176.20
Connecting to download.fedora.redhat.com|209.132.176.220|:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 2013409 (1.9M) [application/x-rpm]
Saving to: `eclipse-nls-da-3.4.0.v20090423085802-1.fc11.noarch.rpm'

100%[=====================================================>] 2,013,409 893K/s in 2.2s

2009-05-26 12:13:15 (893 KB/s) - `eclipse-nls-da-3.4.0.v20090423085802-1.fc11.noarch.rpm' saved [2013409/2013409]

[notting@nostromo: ~]$ rpm -vK eclipse-nls-da-3.4.0.v20090423085802-1.fc11.noarch.rpm
eclipse-nls-da-3.4.0.v20090423085802-1.fc11.noarch.rpm:
Header V3 RSA/SHA256 signature: OK, key ID d22e77f2
Header SHA1 digest: OK (95f13b675653661ed7307e483ac5a40e2da43412)
V3 RSA/SHA256 signature: OK, key ID d22e77f2
MD5 digest: OK (cdf308c1f4ed68d2be00ddd93c9b19ad)
}}}

Works for me.

{{{
[notting@nostromo: ~]$ wget http://download.fedora.redhat.com/pub/fedora/linux/updates/11/x86_64/eclipse-nls-da-3.4.0.v20090423085802-1.fc11.noarch.rpm
--2009-05-26 12:13:12-- http://download.fedora.redhat.com/pub/fedora/linux/updates/11/x86_64/eclipse-nls-da-3.4.0.v20090423085802-1.fc11.noarch.rpm
Resolving download.fedora.redhat.com... 209.132.176.220, 209.132.176.20
Connecting to download.fedora.redhat.com|209.132.176.220|:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 2013409 (1.9M) [application/x-rpm]
Saving to: `eclipse-nls-da-3.4.0.v20090423085802-1.fc11.noarch.rpm'

100%[=====================================================>] 2,013,409 893K/s in 2.2s

2009-05-26 12:13:15 (893 KB/s) - `eclipse-nls-da-3.4.0.v20090423085802-1.fc11.noarch.rpm' saved [2013409/2013409]

[notting@nostromo: ~]$ rpm -vK eclipse-nls-da-3.4.0.v20090423085802-1.fc11.noarch.rpm
eclipse-nls-da-3.4.0.v20090423085802-1.fc11.noarch.rpm:
Header V3 RSA/SHA256 signature: OK, key ID d22e77f2
Header SHA1 digest: OK (95f13b675653661ed7307e483ac5a40e2da43412)
V3 RSA/SHA256 signature: OK, key ID d22e77f2
MD5 digest: OK (cdf308c1f4ed68d2be00ddd93c9b19ad)
}}}

Just tried it again from work and it failed again:
{{{
$ rpm -vK eclipse-nls-da-3.4.0.v20090423085802-1.fc11.noarch.rpm
eclipse-nls-da-3.4.0.v20090423085802-1.fc11.noarch.rpm:
Header V3 RSA/SHA256 signature: BAD, key ID d22e77f2
Header SHA1 digest: OK (95f13b675653661ed7307e483ac5a40e2da43412)
V3 RSA/SHA256 signature: OK, key ID d22e77f2
MD5 digest: OK (cdf308c1f4ed68d2be00ddd93c9b19ad)
}}}

Now what may be different between yours and my cases are that I'm downloading/checking on F-10 plus updates whereas perhaps you're on Rawhide? Might the rpm differences account for this? But why would only this package be affected? No such problem with the -de package:
{{{
$ rpm -vK eclipse-nls-de-3.4.0.v20090423085802-1.fc11.noarch.rpm
eclipse-nls-de-3.4.0.v20090423085802-1.fc11.noarch.rpm:
Header V3 RSA/SHA256 signature: OK, key ID d22e77f2
Header SHA1 digest: OK (4d7460dfd10d3347934956f4265cb45417dc6274)
V3 RSA/SHA256 signature: OK, key ID d22e77f2
MD5 digest: OK (406d1a9380f0c262914727f6c20244a3)
}}}

I discovered the problem (if indeed it is a problem) when running reposync on the F-11 updates repo, using F-10 at home and the same problem manifested on CentOS 5 at work (with Seth's python-hashlib installed).

Just tried it again from work and it failed again:
{{{
$ rpm -vK eclipse-nls-da-3.4.0.v20090423085802-1.fc11.noarch.rpm
eclipse-nls-da-3.4.0.v20090423085802-1.fc11.noarch.rpm:
Header V3 RSA/SHA256 signature: BAD, key ID d22e77f2
Header SHA1 digest: OK (95f13b675653661ed7307e483ac5a40e2da43412)
V3 RSA/SHA256 signature: OK, key ID d22e77f2
MD5 digest: OK (cdf308c1f4ed68d2be00ddd93c9b19ad)
}}}

Now what may be different between yours and my cases are that I'm downloading/checking on F-10 plus updates whereas perhaps you're on Rawhide? Might the rpm differences account for this? But why would only this package be affected? No such problem with the -de package:
{{{
$ rpm -vK eclipse-nls-de-3.4.0.v20090423085802-1.fc11.noarch.rpm
eclipse-nls-de-3.4.0.v20090423085802-1.fc11.noarch.rpm:
Header V3 RSA/SHA256 signature: OK, key ID d22e77f2
Header SHA1 digest: OK (4d7460dfd10d3347934956f4265cb45417dc6274)
V3 RSA/SHA256 signature: OK, key ID d22e77f2
MD5 digest: OK (406d1a9380f0c262914727f6c20244a3)
}}}

I discovered the problem (if indeed it is a problem) when running reposync on the F-11 updates repo, using F-10 at home and the same problem manifested on CentOS 5 at work (with Seth's python-hashlib installed).

This looks like it may be https://bugzilla.redhat.com/show_bug.cgi?id=494049. In any case, it's not sounding like a rel-eng issue.

This looks like it may be https://bugzilla.redhat.com/show_bug.cgi?id=494049. In any case, it's not sounding like a rel-eng issue.

Login to comment on this ticket.

Metadata