Volker wrote:
> On Tue, 2012-09-25 at 09:50 +0000, Müller-Reineke, Matthias wrote:
> > What is missing?
> The public key of the repository. Import it using rpm --import.
I've copied the file to a TUV system. It can be checked there:
~/> rpm --checksig -v tomcat6-6.0.24-45.el6.src.rpm
tomcat6-6.0.24-45.el6.src.rpm:
Header V3 RSA/SHA256 Signature, key ID fd431d51: OK
Header SHA1 digest: OK (906acdd5cf193699ef3028d438b12edf7c934d47)
V3 RSA/SHA256 Signature, key ID fd431d51: OK
MD5 digest: OK (7ec8af89e12e5ba43ee1a97e848e75a4)
http://blog.andreas-haerter.com/2012/03/06/rpm-yum-gpg-key-verification-import-deletion-package-signature-check-cheat-sheet
made me discover packages on the TUV system which contain TUVs public keys. Actually the description of these packages contains the ascii armored keys. Inserting the right one into a disk file and importing it (rpm --import) makes it possible to validate the source rpm on a Scientific Linux 6 system.
Why are these public keys not included into Scientific Linux 6?
Is it prohibited by TUV (from rpm -qi: License: pubkey)?
Matthias