Project

General

Profile

Actions

tickets #167221

closed

security-tools repo signature validation failure

Added by john.wang06@sap.com 3 months ago. Updated 3 months ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Category:
-
Target version:
-
Start date:
2024-09-24
Due date:
% Done:

0%

Estimated time:

Description

Hi SUSE admins,

We tried to install gettext-runtime in our SLES12 SP5 machine from download.opensuse.org and failed with Signature verification failed for file 'repomd.xml' from repository 'security-tools' from https://download.opensuse.org/repositories/security/SLE_12_SP5.

We also noticed that the particular security-tools repo is only updated less than a day ago, which do correspond to the timing of our outage. I have attached the full log from the VM for the zypper installation command.

Would you mind helping us investigating if this is something from the repo side? Thank you so much for your help!

Best,
John

zypper install --force-resolution --no-recommends gettext-runtime
Refreshing service 'Advanced_Systems_Management_Module_x86_64'.
Refreshing service 'Containers_Module_x86_64'.
Refreshing service 'HPC_Module_x86_64'.
Refreshing service 'Legacy_Module_x86_64'.
Refreshing service 'Public_Cloud_Module_x86_64'.
Refreshing service 'SUSE_Linux_Enterprise_Server_x86_64'.
Refreshing service 'SUSE_Linux_Enterprise_Software_Development_Kit_x86_64'.
Refreshing service 'Toolchain_Module_x86_64'.
Refreshing service 'Web_and_Scripting_Module_x86_64'.
Retrieving repository 'security-tools' metadata -------------------------------------------------------------------------------------------------------------------------------------------------------------------------[]
Signature verification failed for file 'repomd.xml' from repository 'security-tools'.

Note: Signing data enables the recipient to verify that no modifications occurred after the data
were signed. Accepting data with no, wrong or unknown signature can lead to a corrupted system
and in extreme cases even to a system compromise.

Note: File 'repomd.xml' is the repositories master index file. It ensures the integrity of the
whole repo.

Warning: This file was modified after it has been signed. This may have been a malicious change,
so it might not be trustworthy anymore! You should not continue unless you know it's safe.

Signature verification failed for file 'repomd.xml' from repository 'security-tools'. Continue? yes/no: no
Retrieving repository 'security-tools' metadata .....................................................................................................................................................................[error]
Repository 'security-tools' is invalid.
[security-tools|https://download.opensuse.org/repositories/security/SLE_12_SP5/] Valid metadata not found at specified URL
Please check if the URIs defined for this repository are pointing to a valid repository.

Actions

Also available in: Atom PDF