keybase / keybase/keybase-issues

openSUSE repomd.xml not signed

Open
#3,412 8 comments 0 reactions 0 assignees View on GitHub
Dominant language
No language data
Stars
899
Forks
40
PR merge metrics
No merged PRs in 30d

Description

When attempting to add `http://prerelease.keybase.io/rpm/$basearch` as a repo on openSUSE, it reports that `repomd.xml` is not digitally signed.

If the repo is added anyway, the `https://keybase.io/docs/server_security/code_signing_key.asc` key is imported, and `run_keybase` is ran afterwards, Keybase seems to start-up and run fine on oS Tumbleweed (can log-in and manage files with the DE's file manager).

![Screenshot from 2019-05-17 17-08-35](https://user-images.githubusercontent.com/6378956/57956294-857e1080-78c6-11e9-8a64-d4db727fb8b9.png)

![Screenshot from 2019-05-17 17-21-41](https://user-images.githubusercontent.com/6378956/57956813-43ee6500-78c8-11e9-9485-0387cd175e99.png)

Contributor guide

No contributing guide indexed for this repository

Research direction

Reproduce the repository setup on openSUSE Tumbleweed using the prerelease.keybase.io RPM source and inspect how its repomd.xml is signed. Compare the repository metadata with the code-signing key at keybase.io/docs/server_security/code_signing_key.asc; done when the repository verifies without bypassing signature checks.

Written by the indexing model from the issue text.

Assessment

Tech stack
linux
Domain
release
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.