Type:
Bug
Priority:
Major
Resolution:
Unresolved
Affects Version/s:
N/A
Component/s:
None
Environment:
CentOS Stream 10
I'm unable to import the GPG signing key for the MariaDB repo in CentOS Stream 10.
# rpm --import https://supplychain.mariadb.com/MariaDB-Server-GPG-KEY
error: Certificate CBCB082A1BB943DB:
Policy rejects CBCB082A1BB943DB: No binding signature at time 2025-01-13T20:09:52Z
error: https://supplychain.mariadb.com/MariaDB-Server-GPG-KEY: key 1 import failed.
After installing sequoia, downloading the GPG key, and examining it, the output show a problem with the SHA-1 signature algorithm. I don't really understand why, as according to the documentation (https://mariadb.com/kb/en/yum/#importing-the-mariadb-gpg-public-key ), this issue was fixed back in 2023.
# dnf install -yq sequoia-sq
# curl -OL https://supplychain.mariadb.com/MariaDB-Server-GPG-KEY
# sq inspect MariaDB-Server-GPG-KEY
MariaDB-Server-GPG-KEY: OpenPGP Certificate.
Fingerprint: 199369E5404BD5FC7D2FE43BCBCB082A1BB943DB
Invalid: No binding signature at time 2025-01-13T20:13:29Z: Policy rejected non-revocation signature (PositiveCertification) requiring second pre-image resistance, because SHA1 is not considered secure
Public-key algo: DSA
Public-key size: 1024 bits
Creation time: 2010-02-02 20:01:20 UTC
Subkey: D40485B86E6B5BDA57EF359E83940066672557E6
Invalid: Policy rejected non-revocation signature (SubkeyBinding) requiring second pre-image resistance
because: SHA1 is not considered secure
Invalid: primary key: No binding signature at time 2025-01-13T20:13:29Z, because Policy rejected non-revocation signature (PositiveCertification) requiring second pre-image resistance, because SHA1 is not considered secure
Public-key algo: ElGamal
Public-key size: 4096 bits
Creation time: 2010-02-02 20:02:00 UTC
UserID: MariaDB Package Signing Key <package-signing-key@mariadb.org>
Invalid: Policy rejected non-revocation signature (PositiveCertification) requiring second pre-image resistance
because: SHA1 is not considered secure
Certifications: 10, use --certifications to list
Note: There is another block of armored OpenPGP data.
Note: This is a non-standard extension to OpenPGP.
MariaDB-Server-GPG-KEY: OpenPGP Certificate.
Fingerprint: 177F4010FE56CA3336300305F1656F24C74CD1D8
Public-key algo: RSA
Public-key size: 4096 bits
Creation time: 2016-03-30 17:45:15 UTC
Key flags: certification, signing
Subkey: A6E773A1812E4B8FD94024AAC0F47944DE8F6914
Public-key algo: RSA
Public-key size: 4096 bits
Creation time: 2016-03-30 17:45:15 UTC
Key flags: transport encryption, data-at-rest encryption
UserID: MariaDB Signing Key <signing-key@mariadb.org>
Certifications: 6, use --certifications to list
Attempting to set the system security policy to "LEGACY" doesn't fix the issue, but does produce a different error.
# update-crypto-policies --set LEGACY
# rpm --import https://supplychain.mariadb.com/MariaDB-Server-GPG-KEY
error: Certificate CBCB082A1BB943DB:
Policy rejects CBCB082A1BB943DB: Policy rejected asymmetric algorithm
error: https://supplychain.mariadb.com/MariaDB-Server-GPG-KEY: key 1 import failed.
# sq inspect MariaDB-Server-GPG-KEY
MariaDB-Server-GPG-KEY: OpenPGP Certificate.
Fingerprint: 199369E5404BD5FC7D2FE43BCBCB082A1BB943DB
Invalid: Policy rejected asymmetric algorithm: DSA1024 is not considered secure
Public-key algo: DSA
Public-key size: 1024 bits
Creation time: 2010-02-02 20:01:20 UTC
Subkey: D40485B86E6B5BDA57EF359E83940066672557E6
Invalid: primary key: Policy rejected asymmetric algorithm, because DSA1024 is not considered secure
Public-key algo: ElGamal
Public-key size: 4096 bits
Creation time: 2010-02-02 20:02:00 UTC
UserID: MariaDB Package Signing Key <package-signing-key@mariadb.org>
Certifications: 10, use --certifications to list
Note: There is another block of armored OpenPGP data.
Note: This is a non-standard extension to OpenPGP.
MariaDB-Server-GPG-KEY: OpenPGP Certificate.
Fingerprint: 177F4010FE56CA3336300305F1656F24C74CD1D8
Public-key algo: RSA
Public-key size: 4096 bits
Creation time: 2016-03-30 17:45:15 UTC
Key flags: certification, signing
Subkey: A6E773A1812E4B8FD94024AAC0F47944DE8F6914
Public-key algo: RSA
Public-key size: 4096 bits
Creation time: 2016-03-30 17:45:15 UTC
Key flags: transport encryption, data-at-rest encryption
UserID: MariaDB Signing Key <signing-key@mariadb.org>
Certifications: 6, use --certifications to list
Reference to the blog post I used to troubleshoot: https://www.redhat.com/en/blog/updating-gpg-keys-for-fedora-and-rhel
relates to
MDBF-847
Add Centos Stream 10 as a CI builder
Open
There are no comments yet on this issue.
{"report":{"fcp":830.7999999970198,"ttfb":174.3999999910593,"pageVisibility":"visible","entityId":132358,"key":"jira.project.issue.view-issue","isInitial":true,"threshold":1000,"elementTimings":{},"userDeviceMemory":8,"userDeviceProcessors":64,"apdex":1,"journeyId":"7909faac-a025-493d-a362-f913e48a0453","navigationType":0,"readyForUser":957.2999999970198,"redirectCount":0,"resourceLoadedEnd":786.2999999970198,"resourceLoadedStart":179.79999999701977,"resourceTiming":[{"duration":181.70000000298023,"initiatorType":"link","name":"https://jira.mariadb.org/s/2c21342762a6a02add1c328bed317ffd-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/css/_super/batch.css","startTime":179.79999999701977,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":179.79999999701977,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":361.5,"responseStart":0,"secureConnectionStart":0},{"duration":181.79999999701977,"initiatorType":"link","name":"https://jira.mariadb.org/s/7ebd35e77e471bc30ff0eba799ebc151-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/css/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":180,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":180,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":361.79999999701977,"responseStart":0,"secureConnectionStart":0},{"duration":191.20000000298023,"initiatorType":"script","name":"https://jira.mariadb.org/s/0917945aaa57108d00c5076fea35e069-CDN/lu2cib/820016/12ta74/0a8bac35585be7fc6c9cc5a0464cd4cf/_/download/contextbatch/js/_super/batch.js?locale=en","startTime":180.19999998807907,"connectEnd":180.19999998807907,"connectStart":180.19999998807907,"domainLookupEnd":180.19999998807907,"domainLookupStart":180.19999998807907,"fetchStart":180.19999998807907,"redirectEnd":0,"redirectStart":0,"requestStart":180.19999998807907,"responseEnd":371.3999999910593,"responseStart":371.3999999910593,"secureConnectionStart":180.19999998807907},{"duration":262.79999999701977,"initiatorType":"script","name":"https://jira.mariadb.org/s/2d8175ec2fa4c816e8023260bd8c1786-CDN/lu2cib/820016/12ta74/494e4c556ecbb29f90a3d3b4f09cb99c/_/download/contextbatch/js/jira.browse.project,project.issue.navigator,jira.view.issue,jira.general,jira.global,atl.general,-_super/batch.js?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&locale=en&slack-enabled=true&whisper-enabled=true","startTime":180.5,"connectEnd":180.5,"connectStart":180.5,"domainLookupEnd":180.5,"domainLookupStart":180.5,"fetchStart":180.5,"redirectEnd":0,"redirectStart":0,"requestStart":180.5,"responseEnd":443.29999999701977,"responseStart":443.29999999701977,"secureConnectionStart":180.5},{"duration":266.40000000596046,"initiatorType":"script","name":"https://jira.mariadb.org/s/a9324d6758d385eb45c462685ad88f1d-CDN/lu2cib/820016/12ta74/c92c0caa9a024ae85b0ebdbed7fb4bd7/_/download/contextbatch/js/atl.global,-_super/batch.js?locale=en","startTime":180.69999998807907,"connectEnd":180.69999998807907,"connectStart":180.69999998807907,"domainLookupEnd":180.69999998807907,"domainLookupStart":180.69999998807907,"fetchStart":180.69999998807907,"redirectEnd":0,"redirectStart":0,"requestStart":180.69999998807907,"responseEnd":447.09999999403954,"responseStart":447.09999999403954,"secureConnectionStart":180.69999998807907},{"duration":266.6000000089407,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-en/jira.webresources:calendar-en.js","startTime":180.8999999910593,"connectEnd":180.8999999910593,"connectStart":180.8999999910593,"domainLookupEnd":180.8999999910593,"domainLookupStart":180.8999999910593,"fetchStart":180.8999999910593,"redirectEnd":0,"redirectStart":0,"requestStart":180.8999999910593,"responseEnd":447.5,"responseStart":447.5,"secureConnectionStart":180.8999999910593},{"duration":266.79999999701977,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:calendar-localisation-moment/jira.webresources:calendar-localisation-moment.js","startTime":181,"connectEnd":181,"connectStart":181,"domainLookupEnd":181,"domainLookupStart":181,"fetchStart":181,"redirectEnd":0,"redirectStart":0,"requestStart":181,"responseEnd":447.79999999701977,"responseStart":447.79999999701977,"secureConnectionStart":181},{"duration":334.70000000298023,"initiatorType":"link","name":"https://jira.mariadb.org/s/b04b06a02d1959df322d9cded3aeecc1-CDN/lu2cib/820016/12ta74/a2ff6aa845ffc9a1d22fe23d9ee791fc/_/download/contextbatch/css/jira.global.look-and-feel,-_super/batch.css","startTime":181.29999999701977,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":181.29999999701977,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":516,"responseStart":0,"secureConnectionStart":0},{"duration":266.90000000596046,"initiatorType":"script","name":"https://jira.mariadb.org/rest/api/1.0/shortcuts/820016/47140b6e0a9bc2e4913da06536125810/shortcuts.js?context=issuenavigation&context=issueaction","startTime":181.3999999910593,"connectEnd":181.3999999910593,"connectStart":181.3999999910593,"domainLookupEnd":181.3999999910593,"domainLookupStart":181.3999999910593,"fetchStart":181.3999999910593,"redirectEnd":0,"redirectStart":0,"requestStart":181.3999999910593,"responseEnd":448.29999999701977,"responseStart":448.29999999701977,"secureConnectionStart":181.3999999910593},{"duration":334.59999999403954,"initiatorType":"link","name":"https://jira.mariadb.org/s/3ac36323ba5e4eb0af2aa7ac7211b4bb-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/css/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.css?jira.create.linked.issue=true","startTime":181.5,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":181.5,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":516.0999999940395,"responseStart":0,"secureConnectionStart":0},{"duration":267,"initiatorType":"script","name":"https://jira.mariadb.org/s/5d5e8fe91fbc506585e83ea3b62ccc4b-CDN/lu2cib/820016/12ta74/d176f0986478cc64f24226b3d20c140d/_/download/contextbatch/js/com.atlassian.jira.projects.sidebar.init,-_super,-project.issue.navigator,-jira.view.issue/batch.js?jira.create.linked.issue=true&locale=en","startTime":181.69999998807907,"connectEnd":181.69999998807907,"connectStart":181.69999998807907,"domainLookupEnd":181.69999998807907,"domainLookupStart":181.69999998807907,"fetchStart":181.69999998807907,"redirectEnd":0,"redirectStart":0,"requestStart":181.69999998807907,"responseEnd":448.69999998807907,"responseStart":448.69999998807907,"secureConnectionStart":181.69999998807907},{"duration":355,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-js/jira.webresources:bigpipe-js.js","startTime":191.29999999701977,"connectEnd":191.29999999701977,"connectStart":191.29999999701977,"domainLookupEnd":191.29999999701977,"domainLookupStart":191.29999999701977,"fetchStart":191.29999999701977,"redirectEnd":0,"redirectStart":0,"requestStart":191.29999999701977,"responseEnd":546.2999999970198,"responseStart":546.2999999970198,"secureConnectionStart":191.29999999701977},{"duration":382.90000000596046,"initiatorType":"script","name":"https://jira.mariadb.org/s/d41d8cd98f00b204e9800998ecf8427e-CDN/lu2cib/820016/12ta74/1.0/_/download/batch/jira.webresources:bigpipe-init/jira.webresources:bigpipe-init.js","startTime":191.3999999910593,"connectEnd":191.3999999910593,"connectStart":191.3999999910593,"domainLookupEnd":191.3999999910593,"domainLookupStart":191.3999999910593,"fetchStart":191.3999999910593,"redirectEnd":0,"redirectStart":0,"requestStart":191.3999999910593,"responseEnd":574.2999999970198,"responseStart":574.2999999970198,"secureConnectionStart":191.3999999910593},{"duration":20.700000002980232,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":527.2999999970198,"connectEnd":527.2999999970198,"connectStart":527.2999999970198,"domainLookupEnd":527.2999999970198,"domainLookupStart":527.2999999970198,"fetchStart":527.2999999970198,"redirectEnd":0,"redirectStart":0,"requestStart":527.2999999970198,"responseEnd":548,"responseStart":548,"secureConnectionStart":527.2999999970198},{"duration":23.799999997019768,"initiatorType":"link","name":"https://jira.mariadb.org/s/d5715adaadd168a9002b108b2b039b50-CDN/lu2cib/820016/12ta74/be4b45e9cec53099498fa61c8b7acba4/_/download/contextbatch/css/jira.project.sidebar,-_super,-project.issue.navigator,-jira.general,-jira.browse.project,-jira.view.issue,-jira.global,-atl.general,-com.atlassian.jira.projects.sidebar.init/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":551.2999999970198,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":551.2999999970198,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":575.0999999940395,"responseStart":0,"secureConnectionStart":0},{"duration":234.40000000596046,"initiatorType":"link","name":"https://jira.mariadb.org/s/50bc9be5bfead1a25e72c1a9338c94f6-CDN/lu2cib/820016/12ta74/e108c7645258ccb43280ed3404e3e949/_/download/contextbatch/css/com.atlassian.jira.plugins.jira-development-integration-plugin:0,-_super,-jira.view.issue,-jira.global,-jira.general,-jira.browse.project,-project.issue.navigator,-atl.general/batch.css?agile_global_admin_condition=true&jag=true&jira.create.linked.issue=true&slack-enabled=true&whisper-enabled=true","startTime":551.8999999910593,"connectEnd":0,"connectStart":0,"domainLookupEnd":0,"domainLookupStart":0,"fetchStart":551.8999999910593,"redirectEnd":0,"redirectStart":0,"requestStart":0,"responseEnd":786.2999999970198,"responseStart":0,"secureConnectionStart":0},{"duration":363.79999999701977,"initiatorType":"xmlhttprequest","name":"https://jira.mariadb.org/rest/webResources/1.0/resources","startTime":649.0999999940395,"connectEnd":649.0999999940395,"connectStart":649.0999999940395,"domainLookupEnd":649.0999999940395,"domainLookupStart":649.0999999940395,"fetchStart":649.0999999940395,"redirectEnd":0,"redirectStart":0,"requestStart":649.0999999940395,"responseEnd":1012.8999999910593,"responseStart":1012.8999999910593,"secureConnectionStart":649.0999999940395}],"fetchStart":1,"domainLookupStart":1,"domainLookupEnd":1,"connectStart":1,"connectEnd":1,"requestStart":8,"responseStart":175,"responseEnd":192,"domLoading":178,"domInteractive":1027,"domContentLoadedEventStart":1027,"domContentLoadedEventEnd":1082,"domComplete":1673,"loadEventStart":1673,"loadEventEnd":1674,"userAgent":"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)","marks":[{"name":"bigPipe.sidebar-id.start","time":1003},{"name":"bigPipe.sidebar-id.end","time":1003.8999999910593},{"name":"bigPipe.activity-panel-pipe-id.start","time":1004.0999999940395},{"name":"bigPipe.activity-panel-pipe-id.end","time":1004.5999999940395},{"name":"activityTabFullyLoaded","time":1089.7999999970198}],"measures":[],"correlationId":"e03546459ec73c","effectiveType":"4g","downlink":10,"rtt":0,"serverDuration":87,"dbReadsTimeInMs":9,"dbConnsTimeInMs":16,"applicationHash":"9d11dbea5f4be3d4cc21f03a88dd11d8c8687422","experiments":[]}}