GPG keys problem

Pavel Hrdina phrdina at redhat.com
Mon Jul 10 10:57:57 UTC 2023


On Fri, Jul 07, 2023 at 03:52:33PM -0700, Todd And Margo Chester wrote:
> Hi All,
> 
> I just updated to Fedora 38 from 37.
> 
> When I do a `# dns update`, my screen gets filled
> with the following (about 20 of them):
> 
> Public key for qemu-user-8.0.0-4.fc37.x86_64.rpm is not trusted. Failing
> package is: qemu-user-2:8.0.0-4.fc37.x86_64
>  GPG Keys are configured as: https://download.copr.fedorainfracloud.org/results/@virtmaint-sig/virt-preview/pubkey.gpg
> 
> How do I fix this?

Hi

recently I've hit the same issue when updating packages. Seems like
Fedora 38 requires newer algorithms and for some reason it was not
updated automatically I had to fix it manually using following commands

Run the following command to get the name of gpg-pubkey for virt-preview
repository:

    rpm -q -a --qf "%{NAME}-%{VERSION}-%{RELEASE} %{SUMMARY}\n" "*gpg*" | grep "virt-preview"

With the correct name run the following command to remove that package:

    rpm -e gpg-pubkey-XXXXXXXX-XXXXXXXX

Now when you "dnf upgrade" it will show you new key that you can verify
and accept the same way when you first enable the virt-preview
repository.

Alternatively you can add the key manually as well before running
"dnf upgrade" using the following command:

    rpm --import https://download.copr.fedorainfracloud.org/results/@virtmaint-sig/virt-preview/pubkey.gpg

Not sure if running only the "rpm --import ..." would fix it as I have
no system to test it on.

Pavel
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://listman.redhat.com/archives/virt-tools-list/attachments/20230710/d79c47bb/attachment.sig>


More information about the virt-tools-list mailing list