GPG key issue, Tor & fedora-23

126 views
Skip to first unread message

Dave Ewart

unread,
Dec 11, 2015, 2:50:54 PM12/11/15
to qubes...@googlegroups.com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Can anyone see what's going wrong here?

I made a clone of fedora-23 as fedora-23-tor in order to start setting
up a TorVM. Inside this new template, I was able to issue

sudo dnf install qubes-tor-repo

without any problem, but then I tried

[user@fedora-23-tor ~]$ sudo dnf install qubes-tor
Last metadata expiration check performed 0:10:54 ago on Fri Dec 11 19:32:16 2015.
Dependencies resolved.
================================================================================
Package Arch Version Repository Size
================================================================================
Installing:
qubes-tor x86_64 0.1.12-1.fc23 qubes-vm-r3.0-current 14 k
tor x86_64 0.2.7.6-tor.1.rh23 tor 2.0 M

Transaction Summary
================================================================================
Install 2 Packages

Total download size: 2.0 M
Installed size: 8.2 M
Is this ok [y/N]: y
Downloading Packages:
(1/2): qubes-tor-0.1.12-1.fc23.x86_64.rpm 25 kB/s | 14 kB 00:00
(2/2): tor-0.2.7.6-tor.1.rh23.x86_64.rpm 1.4 MB/s | 2.0 MB 00:01
--------------------------------------------------------------------------------
Total 1.4 MB/s | 2.0 MB 00:01
warning: /var/cache/dnf/tor-97acf837743c6c6d/packages/tor-0.2.7.6-tor.1.rh23.x86_64.rpm: Header V4 RSA/SHA1 Signature, key ID f4b85e0f: NOKEY
Importing GPG key 0x5AC001F1:
Userid : "torproject.org RPM signing key"
Fingerprint: 3B9E EEB9 7B1E 827B CF0A 0D96 8AF5 653C 5AC0 01F1
From : /etc/pki/rpm-gpg/RPM-GPG-KEY-torproject.org.asc
Is this ok [y/N]: y
Key imported successfully
Import of key(s) didn't help, wrong key(s)?
The downloaded packages were saved in cache till the next successful transaction.
You can remove cached packages by executing 'dnf clean packages'.
Error: Public key for tor-0.2.7.6-tor.1.rh23.x86_64.rpm is not installed


Failing package is: tor-0.2.7.6-tor.1.rh23.x86_64
GPG Keys are configured as: file:///etc/pki/rpm-gpg/RPM-GPG-KEY-torproject.org.asc

The key is installed:

[user@fedora-23-tor ~]$ rpm -qa gpg-pubkey*
gpg-pubkey-03fa5082-546c9ad2
gpg-pubkey-7fac5991-4615767f
gpg-pubkey-a3c773ad-546e036b
gpg-pubkey-34ec9cba-54e38751
gpg-pubkey-5ac001f1-50253efb

Even using 'sudo rpm --import
/etc/pki/rpm-gpg/RPM-GPG-KEY-torproject.org.asc' doesn't seem to help.

What am I missing?

Dave.

- --
Dave Ewart da...@sungate.co.uk, http://twitter.com/DaveEwart
All email from me is digitally signed, http://www.sungate.co.uk/
GPG key updated Jan 2013 see http://www.sungate.co.uk/gpg
Fingerprint: CF3A 93EF 01E6 16C5 AE7A 1D27 45E1 E473 378B B197
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQQcBAEBCgAGBQJWaykWAAoJEEXh5HM3i7GXdJof+gLiKXGtsNB7qer3ZInHS/Z1
n+SEsP6aPWo/PV6kY9wmM6vVIchBiimR4+o+OGt8+O9GmXMSlqZEXBw+S4Tezr/4
bQLBrm12XQbvLT426RxBHa1nwfy0xoKjt2886ZjEKJQ1SicQwhbYlk37dFS+KyYQ
iX1iTrW3f9rPyuDQmAU0v+kL/CBK0mmj+9LFADkPmx4OCwdwLltoU5yEZL4MIdvw
2jmt7Sda/wtcVzOvmZfyoyoS8GML8hl9In8hRKJ+QP8+w+LbHLOzbDmQz33xIoh9
MkEZPEuyE6aExO7fu0G+ETNWliCTOyX9r1iVnFj3z0hMdjX5WyKIHxjwBv1I7g6b
U5i91QjkuMA56TF97+Mgx+M3ruM7Y7yDtr3c0fXivm9h6tq9Ut7SkgOrJDecs6X1
AYYzMzDhoMZpRxXInMwCD1u3+lgjp/KyLvdV5+al5G9YO8nfkFcACWIQZVMXI38Q
tLLnBpToWa8D3E1SLgeHl1L+knHdvoZg47s6iXJz/QKleFmnr4fIWYdNfk9rqVJG
+Wj6BHeWdeYhr7swE1iXE+Nt4bQ9XuEJQtvgRCGRp7Df3Jfg2OjSlEZ0WaTKhxxT
cpxW3FgBdeKR9lvD4QzeMW+gcDb0zurEbEXJgmBOg5NzsXqr3zpGTyzo3JMWFhVu
qrI6In4falc6q4zRBEUk0AGQCDV60G8SkCdeqdmYMBcOaGoCF2kUkICXcjqIt11o
Dos2c0lqlXILfNdIfi+cwUezSeDK9ql+bt69T0GsvUlxJMCOjErOUhUZnethrSwv
7dus4mVSRaVxOJqUWPWl2iYnWrMsHG6qhkhNeeFKlUyqXP1JHVVJRBWXci+NVJ3K
Jx5HPEY2LzXxEH5UdPLsJc1ITJHY8/E9Ssxk7JtS1GINv0pCVKrrDwR9bCobrT5O
Zyyg2ETM2wu9DPZYmiwA8DHzhjcG1SktjEW3m5ZuotC4X4KrsJGytPZLn887JCJN
TMbcdNa4W/jtQcRC3cHThA3oITal273QggiRKw2SwAHt8WRoyqDwzN15ZHj9Olpr
ZLLZq8WSqJEgBDZmMie9V+S7flP9z8lY8vUL41vtLHQ1gYEB0vJbEX3w9dKEA2uA
RPMl+BkKVR5rfy1njDEYRSeG2Nlm5l7+VzJPkuRApo/Fw6WOhCbw+/Hnl5ktUN7g
f9+zD4JDf01WImgDR5Q67kDwssNbf8dnfkuV7h5qLSQ9MHts6jyKfD3+myKU1pOO
t4CuVr9LjHajCRdJNty4iFxgcjel2p1JNFvSyxtUYkCHHw6zUWjiOXGklgW2dKS6
A/gX8mPyqb+JvDgGpefpefgkC1Nogz43280IqqDZ4mV5NPX905offnfm9SpygMI=
=Dczt
-----END PGP SIGNATURE-----

Marek Marczykowski-Górecki

unread,
Dec 11, 2015, 3:13:39 PM12/11/15
to qubes...@googlegroups.com, da...@sungate.co.uk
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
Tor project changed their package signing key. Package with new key
(qubes-tor-repo-0.1.14) is currently in testing repository. You can
install it adding `--enablerepo=qubes-*testing` to dnf cmdline.

- --
Best Regards,
Marek Marczykowski-Górecki
Invisible Things Lab
A: Because it messes up the order in which people normally read text.
Q: Why is top-posting such a bad thing?
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQEcBAEBCAAGBQJWay5qAAoJENuP0xzK19csIUAH/jG1gd0ahVT3tZgE0Z4z1Vex
7231MBkd+gU8Nu2Zw0jFaBx22aZS/2u5iF4wNNUA2K3r56Eu1JXQepOLvjQZtQpH
DHhdnA/FR+FBaX+m6a97yhS2f/SQJDuv4WDlFmhCzbbebTgg2Trw3ARr8EqgHTbo
4cfJDANW3sNelhV3SDwZjcZbJgfJyumA/Hc1ebsECUFzkme+4qlXLJodQudgfe0L
X0q6469h3T3ytuVuv5S1Sv61PhAGnlJ3NUArcpjB9tSVUuoG2veJCxLMe3aOg7eK
f3wWYTQcbcjU0E/y7hrs0qqAseylZXQMePBWFAq9q/g7MuShxc+kbbJONRBx//A=
=VMF3
-----END PGP SIGNATURE-----

Dave Ewart

unread,
Dec 11, 2015, 3:34:01 PM12/11/15
to qubes...@googlegroups.com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

On Friday, 11.12.2015 at 21:13 +0100, Marek Marczykowski-Górecki wrote:

> > [...]
> >
> > What am I missing?
>
> Tor project changed their package signing key. Package with new key
> (qubes-tor-repo-0.1.14) is currently in testing repository. You can
> install it adding `--enablerepo=qubes-*testing` to dnf cmdline.

Ah, excellent, thanks Marek for your quick response. :-D

Dave.

- --
Dave Ewart da...@sungate.co.uk, http://twitter.com/DaveEwart
All email from me is digitally signed, http://www.sungate.co.uk/
GPG key updated Jan 2013 see http://www.sungate.co.uk/gpg
Fingerprint: CF3A 93EF 01E6 16C5 AE7A 1D27 45E1 E473 378B B197
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iQQcBAEBCgAGBQJWazM2AAoJEEXh5HM3i7GXtacf/0qj8Cu87RNdPrusycoNlQSz
8B+d2BN9qKg43iIdYsyKArhL3cTWw8ZDmjjWStI8DzqaJGdN3hCg5X+gg13mh/sg
oSlY+WwxJHN1X+QnXRmc6ZqGQ/9SBhn8LsdNiQDwhrQpbq1YnqcXkSkJBOgZuL0J
9FPCSluJT+7RE1dFLCvKdB6weGcFDFZ99zQG4s36TTHIvOQ5vYhnvthydgB+vgnf
qBjD6woMBTTfRv2tYb1wmJ+W85ZrsofASWLlt0r3Wdb0TQSCX2M0j1tC0KXAlUXC
vtTcRBWf01YHYmwYnvG4HeV2AlPuquq60PN+VQ+52DSAhHB3e9c765bFUjoN8JnY
YWxl5JAkqPwctlttj+J0/D42wTHgd5njwcsec3Q175pLyLdVnqq0+LFr1roIjIwQ
i1weqasKa4QY+AuxV8EZSzbNybRvQXjaewyBW+c8qEJSGExeNJXOa4OckhT+mPXg
FH1uQg6YzObHB3jTdCToOgVkgU+QeNTOyH5jbaHXWUv4DtYG0oF3L1QW6MXSZBul
jLLDsFwhKOZCc5Nir79aCf3MW8WF/JAdOYy4g3fXAbqZD6K39n+CEnI1ng1sL/sE
1bQmRIi5LdkomRNBGvr7tDstHH5xfXYm7z020iOJZHRpf9KN0Mb9QN3J7pE81iLO
3SCAi9x94aoBzLRnJQlidaxatmLTItnvsUOVEAzGvNFzq215cShMKoPd4XEXrTbV
xrfmCYgov/fDH838NLJ8l/izvBdN7689xhEgMLuqsqqQyDCXNJi/w189seyY/x5s
RJVQcLRuCiUnq26oksywxOm4F7rMCl9muvCoR3nN6rnYolNoMKDF6l6LYn/tUbTD
KqO8a9h5MxsKZ8OIXP1Ve6N/+ufDWM5Oo3avu/SSdfq06fhsHI/KXxdoQYP9o++/
KHQtNjRV1r4DMLDNk7uTrkS596WZgNqhfOrK9BjK7ORTfI3BkKSQl8pd5MiTESLA
igT0CzHMIWSduTlParQ3IAJvsOunTVrNkVbjreujGudlqVYeKLLeN2PWSHHtOHKx
MwtjyfiChbNs+9XyRwfkejiz0czIvWzJMQJdZDM7r+NzYbtuWhqcrvdJuyRKBu3u
FH+WFLjfebKYR8z4CRbC8Ytd6txPs1PsuXgcCFRq5hECPjX0FdPk6Wxs6uEkL5wq
0mvJVXy5d6Wp7McbuZ4AZPfHWnxR/fyuGsUUh3kAw1yIyzLexaZ0RId+mWuHlmfF
bfzw0rc1lNYeul5PXleNUjj/Yq9hULU9RvcJMswwd+7gKQHSS3PuUfmo0jQ9pe80
oHjkR2A+6XNLPfmWohq2fWOiFEhwGHK8XhL1WWu8D3v0I+5sQ6gOKPtMqUs0k/k=
=APNF
-----END PGP SIGNATURE-----
Reply all
Reply to author
Forward
0 new messages