keybase / keybase/client

openSUSE: Signature verification failed for file 'repomd.xml'

Open
#19,494 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Go
Stars
9.2k
Forks
1.3k
Avg merge
12h 58m
Merged PRs (30d)
56

Description

Hi,
Thanks for the great work.
I installed keybase from the RPM on openSUSE with no problems and it seems to work fine. The RPM did not add the repo to my system as indicated in the install page. I added the repo manually but when I refresh the repos I get the following error:

`
Signature verification failed for file "repomd.xml" from repository "keybase".

Note: Signing data enables the recipient to verify that no modifications occurred after the data
were signed. Accepting data with no, wrong or unknown signature can lead to a corrupted system
and in extreme cases even to a system compromise.

Note: File "repomd.xml" is the repositories master index file. It ensures the integrity of the
whole repo.

Warning: This file was modified after it has been signed. This may have been a malicious change,
so it might not be trustworthy anymore! You should not continue unless you know it's safe.

Signature verification failed for file "repomd.xml" from repository "keybase". Continue? [yes/no] (no):
`
Please advise,
Thanks

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the openSUSE RPM installation and the repository setup described in the issue, then reproduce the repomd.xml refresh error on openSUSE. Review the repository signing and release configuration; done means the keybase repository refreshes without signature verification warnings.

Written by the indexing model from the issue text.

Assessment

Tech stack
linux
Domain
release, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.