Thread: RHEL8: pgadmin4 repo file bad gpg signature

RHEL8: pgadmin4 repo file bad gpg signature

From
Cameron Murdoch
Date:
Hi,

On RHEL8 here with freshly installed pgadmin4 repo:

dnf list available --repo pgAdmin4
Updating Subscription Management repositories.
pgadmin4                                                              
2.3 kB/s | 833  B     00:00    
pgadmin4                                                              
3.8 MB/s | 3.8 kB     00:00    
pgadmin4                                                              
1.2 kB/s | 833  B     00:00    
Error: Failed to download metadata for repo 'pgAdmin4': repomd.xml GPG
signature verification error: Bad GPG signature

Looking at for example:
https://ftp.postgresql.org/pub/pgadmin/pgadmin4/yum/redhat/rhel-8-x86_64/repodata/
The timestamps for repomd.xml and repoxml.xml.asc are different by
about 2 days. Downloading these and verifying manually gives:


gpg --verify repomd.xml.asc repomd.xml
gpg: Signature made Thu 20 Oct 2022 12:41:38 CEST
gpg:                using RSA key
E8697E2EEF76C02D3A6332778881B2A8210976F2
gpg: BAD signature from "Package Manager (Package Signing Key)
<packages@pgadmin.org>" [unknown]

Thanks,

Cameron

Re: RHEL8: pgadmin4 repo file bad gpg signature

From
Devrim Gündüz
Date:
Hi,

pgAdmin4 packaging is done by pgAdmin team itself. Please report this
issue here:

https://github.com/pgadmin-org/pgadmin4/issues

Regards, Devrim

On Fri, 2022-11-18 at 15:04 +0000, Cameron Murdoch wrote:
> Hi,
>
> On RHEL8 here with freshly installed pgadmin4 repo:
>
> dnf list available --repo pgAdmin4
> Updating Subscription Management repositories.
> pgadmin4                                                             
> 2.3 kB/s | 833  B     00:00   
> pgadmin4                                                             
> 3.8 MB/s | 3.8 kB     00:00   
> pgadmin4                                                             
> 1.2 kB/s | 833  B     00:00   
> Error: Failed to download metadata for repo 'pgAdmin4': repomd.xml
> GPG
> signature verification error: Bad GPG signature
>
> Looking at for example:
> https://ftp.postgresql.org/pub/pgadmin/pgadmin4/yum/redhat/rhel-8-x86_64/repodata/
> The timestamps for repomd.xml and repoxml.xml.asc are different by
> about 2 days. Downloading these and verifying manually gives:
>
>
> gpg --verify repomd.xml.asc repomd.xml
> gpg: Signature made Thu 20 Oct 2022 12:41:38 CEST
> gpg:                using RSA key
> E8697E2EEF76C02D3A6332778881B2A8210976F2
> gpg: BAD signature from "Package Manager (Package Signing Key)
> <packages@pgadmin.org>" [unknown]
>
> Thanks,
>
> Cameron

--
Devrim Gündüz
Open Source Solution Architect, Red Hat Certified Engineer
Twitter: @DevrimGunduz , @DevrimGunduzTR

Attachment