Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 841985 - gpg --chec-sigs shows 1 bad signature
Summary: gpg --chec-sigs shows 1 bad signature
Status: UNCONFIRMED
Alias: None
Product: Gentoo Infrastructure
Classification: Unclassified
Component: Other (show other bugs)
Hardware: AMD64 Linux
: Normal normal (vote)
Assignee: Gentoo Infrastructure
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2022-05-01 08:06 UTC by de_johannes
Modified: 2022-08-25 07:01 UTC (History)
4 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
output of "gpg --check-sigs" (output,10.20 KB, text/plain)
2022-05-01 08:06 UTC, de_johannes
Details

Note You need to log in before you can comment on or make changes to this bug.
Description de_johannes 2022-05-01 08:06:24 UTC
Created attachment 775763 [details]
output of "gpg --check-sigs"

After obtaineing the service-keys.gpg file from 

https://qa-reports.gentoo.org/output/service-keys.gpg

I ran "gpg --check-sigs", which gave the output attached with this report. It shows that 

gpg: 13 good signatures
gpg: 1 bad signature
gpg: 12 signatures not checked due to missing keys

I suspect that it is connected to this key 

pub   rsa4096 2009-08-25 [SC] [expires: 2023-07-01]
      13EBBDBEDE7A12775DFDB1BABB572E0E2D182910
uid           [ unknown] Gentoo Linux Release Engineering (Automated Weekly Release Key) <releng@gentoo.org>

as this is the only place where a minus sign shows up ("sig-3" insted of "sig!3"). Another member of the #gentoo Channel confirmed this behaviour. 
Maybe a disclaimer should be added to 

https://www.gentoo.org/downloads/signatures/

What do you think? 

Kind regards and thank your for your time,
Quarz
Comment 1 Alec Warner (RETIRED) archtester gentoo-dev Security 2022-05-01 16:39:17 UTC
Release team, any ideas?

-A
Comment 2 Joe Kappus 2022-08-25 07:01:58 UTC
I just received another report of this happening with a friend while fetching keys from hkps://keys.gentoo.org.

Told him it was likely something in gentoo infra screwing up, suggested --keyserver keyserver.ubuntu.com and it worked to pull valid signatures.