
Hi All, We just picked up a GPG Key error when running `dnf install ovirt-engine-appliance` in preparation of a fresh oVirt v4.5.5 install on RL v9.3: ~~~ oVirt upstream for CentOS Stream 9 - oVirt 4.5 79 kB/s | 1.6 kB 00:00 Importing GPG key 0x24901D0C: Userid : "oVirt <infra@ovirt.org>" Fingerprint: 3C98 E81D B93D EA6D 54DE 690E 44E4 75CB 2490 1D0C From : /etc/pki/rpm-gpg/RPM-GPG-KEY-oVirt-4.5 Is this ok [y/N]: y Key imported successfully Import of key(s) didn't help, wrong key(s)? Public key for ovirt-engine-appliance-4.5-20231201120201.1.el9.x86_64.rpm is not installed. Failing package is: ovirt-engine-appliance-4.5-20231201120201.1.el9.x86_64 GPG Keys are configured as: file:///etc/pki/rpm-gpg/RPM-GPG-KEY-oVirt-4.5 ~~~ An error? An issue with the repo definition? Can it safely be ignored (normally I'd say "No" but its from the oVirt Tam's own repo...)? Is the fingerprint above the correct one (and for that matter, where is the GPG Key's Fingerprint recorded on the oVirt Website so that we can check compliance ourselves)? Anyway, thought I'd let people know (further details can be provide upon request) Cheers Dulux-Oz

Hi. Why don't you use the ISO and just install the hosts using it, and then deploy the engine? Why install on RHEL now... I've been using CentOS Stream 9 with UEFI for about 6 months and everything is working... Cheers! Em seg., 8 de jan. de 2024 às 04:07, Matthew J Black < matthew@peregrineit.net> escreveu:
Hi All,
We just picked up a GPG Key error when running `dnf install ovirt-engine-appliance` in preparation of a fresh oVirt v4.5.5 install on RL v9.3:
~~~ oVirt upstream for CentOS Stream 9 - oVirt 4.5 79 kB/s | 1.6 kB 00:00 Importing GPG key 0x24901D0C: Userid : "oVirt <infra@ovirt.org>" Fingerprint: 3C98 E81D B93D EA6D 54DE 690E 44E4 75CB 2490 1D0C From : /etc/pki/rpm-gpg/RPM-GPG-KEY-oVirt-4.5 Is this ok [y/N]: y Key imported successfully Import of key(s) didn't help, wrong key(s)? Public key for ovirt-engine-appliance-4.5-20231201120201.1.el9.x86_64.rpm is not installed. Failing package is: ovirt-engine-appliance-4.5-20231201120201.1.el9.x86_64 GPG Keys are configured as: file:///etc/pki/rpm-gpg/RPM-GPG-KEY-oVirt-4.5 ~~~
An error? An issue with the repo definition? Can it safely be ignored (normally I'd say "No" but its from the oVirt Tam's own repo...)? Is the fingerprint above the correct one (and for that matter, where is the GPG Key's Fingerprint recorded on the oVirt Website so that we can check compliance ourselves)?
Anyway, thought I'd let people know (further details can be provide upon request)
Cheers
Dulux-Oz _______________________________________________ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-leave@ovirt.org Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/WILIDSO6CMHHJL...
-- Att, Jorge Visentini +55 55 98432-9868

Hi Jorge, It's actually Rocky Linux v9.3 - I was using the term "RHEL" genrically - I suppose I should have used "EL" or "RL" instead. On 09/01/2024 00:20, Jorge Visentini wrote:
Hi.
Why don't you use the ISO and just install the hosts using it, and then deploy the engine? Why install on RHEL now... I've been using CentOS Stream 9 with UEFI for about 6 months and everything is working...
Cheers!
Em seg., 8 de jan. de 2024 às 04:07, Matthew J Black <matthew@peregrineit.net> escreveu:
Hi All,
We just picked up a GPG Key error when running `dnf install ovirt-engine-appliance` in preparation of a fresh oVirt v4.5.5 install on RL v9.3:
~~~ oVirt upstream for CentOS Stream 9 - oVirt 4.5 79 kB/s | 1.6 kB 00:00 Importing GPG key 0x24901D0C: Userid : "oVirt <infra@ovirt.org>" Fingerprint: 3C98 E81D B93D EA6D 54DE 690E 44E4 75CB 2490 1D0C From : /etc/pki/rpm-gpg/RPM-GPG-KEY-oVirt-4.5 Is this ok [y/N]: y Key imported successfully Import of key(s) didn't help, wrong key(s)? Public key for ovirt-engine-appliance-4.5-20231201120201.1.el9.x86_64.rpm is not installed. Failing package is: ovirt-engine-appliance-4.5-20231201120201.1.el9.x86_64 GPG Keys are configured as: file:///etc/pki/rpm-gpg/RPM-GPG-KEY-oVirt-4.5 ~~~
An error? An issue with the repo definition? Can it safely be ignored (normally I'd say "No" but its from the oVirt Tam's own repo...)? Is the fingerprint above the correct one (and for that matter, where is the GPG Key's Fingerprint recorded on the oVirt Website so that we can check compliance ourselves)?
Anyway, thought I'd let people know (further details can be provide upon request)
Cheers
Dulux-Oz _______________________________________________ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-leave@ovirt.org Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/WILIDSO6CMHHJL...
-- Att, Jorge Visentini +55 55 98432-9868
-- This email has been checked for viruses by Avast antivirus software. www.avast.com

Hi Matthew, I reported this like 3 weeks ago :( just use dnf -y install ovirt-engine-appliance --nogpgcheck before hosted-engine --deploy Jirka On 1/8/24 17:14, Matthew J Black wrote:
Hi Jorge,
It's actually Rocky Linux v9.3 - I was using the term "RHEL" genrically - I suppose I should have used "EL" or "RL" instead.
On 09/01/2024 00:20, Jorge Visentini wrote:
Hi.
Why don't you use the ISO and just install the hosts using it, and then deploy the engine? Why install on RHEL now... I've been using CentOS Stream 9 with UEFI for about 6 months and everything is working...
Cheers!
Em seg., 8 de jan. de 2024 às 04:07, Matthew J Black <matthew@peregrineit.net> escreveu:
Hi All,
We just picked up a GPG Key error when running `dnf install ovirt-engine-appliance` in preparation of a fresh oVirt v4.5.5 install on RL v9.3:
~~~ oVirt upstream for CentOS Stream 9 - oVirt 4.5 79 kB/s | 1.6 kB 00:00 Importing GPG key 0x24901D0C: Userid : "oVirt <infra@ovirt.org>" Fingerprint: 3C98 E81D B93D EA6D 54DE 690E 44E4 75CB 2490 1D0C From : /etc/pki/rpm-gpg/RPM-GPG-KEY-oVirt-4.5 Is this ok [y/N]: y Key imported successfully Import of key(s) didn't help, wrong key(s)? Public key for ovirt-engine-appliance-4.5-20231201120201.1.el9.x86_64.rpm is not installed. Failing package is: ovirt-engine-appliance-4.5-20231201120201.1.el9.x86_64 GPG Keys are configured as: file:///etc/pki/rpm-gpg/RPM-GPG-KEY-oVirt-4.5 ~~~
An error? An issue with the repo definition? Can it safely be ignored (normally I'd say "No" but its from the oVirt Tam's own repo...)? Is the fingerprint above the correct one (and for that matter, where is the GPG Key's Fingerprint recorded on the oVirt Website so that we can check compliance ourselves)?
Anyway, thought I'd let people know (further details can be provide upon request)
Cheers
Dulux-Oz _______________________________________________ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-leave@ovirt.org Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/WILIDSO6CMHHJL...
-- Att, Jorge Visentini +55 55 98432-9868
<https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=emailclient> Virus-free.www.avast.com <https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=emailclient>
<#DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2>
_______________________________________________ Users mailing list --users@ovirt.org To unsubscribe send an email tousers-leave@ovirt.org Privacy Statement:https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct:https://www.ovirt.org/community/about/community-guidelines/ List Archives:https://lists.ovirt.org/archives/list/users@ovirt.org/message/QP52KSI67LRMVE...

Hi Jirka and Matthew, We think that we resolved the issue, which included re-signing the packages and re-creating the oVirt 4.5 yum repo. Could you please try to re-fetch the packages in question and see if that solves the problem for you? Thanks in advance and sorry for the issue, On Tue, Jan 9, 2024 at 1:34 PM Jirka Simon <jirka@vesim.cz> wrote:
Hi Matthew,
I reported this like 3 weeks ago :(
just use dnf -y install ovirt-engine-appliance --nogpgcheck before hosted-engine --deploy
Jirka On 1/8/24 17:14, Matthew J Black wrote:
Hi Jorge,
It's actually Rocky Linux v9.3 - I was using the term "RHEL" genrically - I suppose I should have used "EL" or "RL" instead. On 09/01/2024 00:20, Jorge Visentini wrote:
Hi.
Why don't you use the ISO and just install the hosts using it, and then deploy the engine? Why install on RHEL now... I've been using CentOS Stream 9 with UEFI for about 6 months and everything is working...
Cheers!
Em seg., 8 de jan. de 2024 às 04:07, Matthew J Black < matthew@peregrineit.net> escreveu:
Hi All,
We just picked up a GPG Key error when running `dnf install ovirt-engine-appliance` in preparation of a fresh oVirt v4.5.5 install on RL v9.3:
~~~ oVirt upstream for CentOS Stream 9 - oVirt 4.5 79 kB/s | 1.6 kB 00:00 Importing GPG key 0x24901D0C: Userid : "oVirt <infra@ovirt.org>" Fingerprint: 3C98 E81D B93D EA6D 54DE 690E 44E4 75CB 2490 1D0C From : /etc/pki/rpm-gpg/RPM-GPG-KEY-oVirt-4.5 Is this ok [y/N]: y Key imported successfully Import of key(s) didn't help, wrong key(s)? Public key for ovirt-engine-appliance-4.5-20231201120201.1.el9.x86_64.rpm is not installed. Failing package is: ovirt-engine-appliance-4.5-20231201120201.1.el9.x86_64 GPG Keys are configured as: file:///etc/pki/rpm-gpg/RPM-GPG-KEY-oVirt-4.5 ~~~
An error? An issue with the repo definition? Can it safely be ignored (normally I'd say "No" but its from the oVirt Tam's own repo...)? Is the fingerprint above the correct one (and for that matter, where is the GPG Key's Fingerprint recorded on the oVirt Website so that we can check compliance ourselves)?
Anyway, thought I'd let people know (further details can be provide upon request)
Cheers
Dulux-Oz _______________________________________________ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-leave@ovirt.org Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/WILIDSO6CMHHJL...
-- Att, Jorge Visentini +55 55 98432-9868
<https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=emailclient> Virus-free.www.avast.com <https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=emailclient> <#m_3968352809059148212_DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2>
_______________________________________________ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-leave@ovirt.org Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/QP52KSI67LRMVE...
_______________________________________________ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-leave@ovirt.org Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/GWLT4VZBP4DOOA...

Hello there, I already finished my installation, but I can try it on sandbox. Jirka On 1/9/24 14:58, Lev Veyde wrote:
Hi Jirka and Matthew,
We think that we resolved the issue, which included re-signing the packages and re-creating the oVirt 4.5 yum repo.
Could you please try to re-fetch the packages in question and see if that solves the problem for you?
Thanks in advance and sorry for the issue,
On Tue, Jan 9, 2024 at 1:34 PM Jirka Simon <jirka@vesim.cz> wrote:
Hi Matthew,
I reported this like 3 weeks ago :(
just use dnf -y install ovirt-engine-appliance --nogpgcheck before hosted-engine --deploy
Jirka
On 1/8/24 17:14, Matthew J Black wrote:
Hi Jorge,
It's actually Rocky Linux v9.3 - I was using the term "RHEL" genrically - I suppose I should have used "EL" or "RL" instead.
On 09/01/2024 00:20, Jorge Visentini wrote:
Hi.
Why don't you use the ISO and just install the hosts using it, and then deploy the engine? Why install on RHEL now... I've been using CentOS Stream 9 with UEFI for about 6 months and everything is working...
Cheers!
Em seg., 8 de jan. de 2024 às 04:07, Matthew J Black <matthew@peregrineit.net> escreveu:
Hi All,
We just picked up a GPG Key error when running `dnf install ovirt-engine-appliance` in preparation of a fresh oVirt v4.5.5 install on RL v9.3:
~~~ oVirt upstream for CentOS Stream 9 - oVirt 4.5 79 kB/s | 1.6 kB 00:00 Importing GPG key 0x24901D0C: Userid : "oVirt <infra@ovirt.org>" Fingerprint: 3C98 E81D B93D EA6D 54DE 690E 44E4 75CB 2490 1D0C From : /etc/pki/rpm-gpg/RPM-GPG-KEY-oVirt-4.5 Is this ok [y/N]: y Key imported successfully Import of key(s) didn't help, wrong key(s)? Public key for ovirt-engine-appliance-4.5-20231201120201.1.el9.x86_64.rpm is not installed. Failing package is: ovirt-engine-appliance-4.5-20231201120201.1.el9.x86_64 GPG Keys are configured as: file:///etc/pki/rpm-gpg/RPM-GPG-KEY-oVirt-4.5 ~~~
An error? An issue with the repo definition? Can it safely be ignored (normally I'd say "No" but its from the oVirt Tam's own repo...)? Is the fingerprint above the correct one (and for that matter, where is the GPG Key's Fingerprint recorded on the oVirt Website so that we can check compliance ourselves)?
Anyway, thought I'd let people know (further details can be provide upon request)
Cheers
Dulux-Oz _______________________________________________ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-leave@ovirt.org Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/WILIDSO6CMHHJL...
-- Att, Jorge Visentini +55 55 98432-9868
<https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=emailclient> Virus-free.www.avast.com <https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=emailclient>
<#m_3968352809059148212_DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2>
_______________________________________________ Users mailing list --users@ovirt.org To unsubscribe send an email tousers-leave@ovirt.org Privacy Statement:https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct:https://www.ovirt.org/community/about/community-guidelines/ List Archives:https://lists.ovirt.org/archives/list/users@ovirt.org/message/QP52KSI67LRMVE...
_______________________________________________ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-leave@ovirt.org Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/GWLT4VZBP4DOOA...

Hi Jirka, If you can, then please do, as we want to verify that we fixed the issue for our users. Thanks in advance, On Tue, Jan 9, 2024 at 9:29 PM Jirka Simon <jirka@vesim.cz> wrote:
Hello there,
I already finished my installation, but I can try it on sandbox.
Jirka
On 1/9/24 14:58, Lev Veyde wrote:
Hi Jirka and Matthew,
We think that we resolved the issue, which included re-signing the packages and re-creating the oVirt 4.5 yum repo.
Could you please try to re-fetch the packages in question and see if that solves the problem for you?
Thanks in advance and sorry for the issue,
On Tue, Jan 9, 2024 at 1:34 PM Jirka Simon <jirka@vesim.cz> wrote:
Hi Matthew,
I reported this like 3 weeks ago :(
just use dnf -y install ovirt-engine-appliance --nogpgcheck before hosted-engine --deploy
Jirka On 1/8/24 17:14, Matthew J Black wrote:
Hi Jorge,
It's actually Rocky Linux v9.3 - I was using the term "RHEL" genrically - I suppose I should have used "EL" or "RL" instead. On 09/01/2024 00:20, Jorge Visentini wrote:
Hi.
Why don't you use the ISO and just install the hosts using it, and then deploy the engine? Why install on RHEL now... I've been using CentOS Stream 9 with UEFI for about 6 months and everything is working...
Cheers!
Em seg., 8 de jan. de 2024 às 04:07, Matthew J Black < matthew@peregrineit.net> escreveu:
Hi All,
We just picked up a GPG Key error when running `dnf install ovirt-engine-appliance` in preparation of a fresh oVirt v4.5.5 install on RL v9.3:
~~~ oVirt upstream for CentOS Stream 9 - oVirt 4.5 79 kB/s | 1.6 kB 00:00 Importing GPG key 0x24901D0C: Userid : "oVirt <infra@ovirt.org>" Fingerprint: 3C98 E81D B93D EA6D 54DE 690E 44E4 75CB 2490 1D0C From : /etc/pki/rpm-gpg/RPM-GPG-KEY-oVirt-4.5 Is this ok [y/N]: y Key imported successfully Import of key(s) didn't help, wrong key(s)? Public key for ovirt-engine-appliance-4.5-20231201120201.1.el9.x86_64.rpm is not installed. Failing package is: ovirt-engine-appliance-4.5-20231201120201.1.el9.x86_64 GPG Keys are configured as: file:///etc/pki/rpm-gpg/RPM-GPG-KEY-oVirt-4.5 ~~~
An error? An issue with the repo definition? Can it safely be ignored (normally I'd say "No" but its from the oVirt Tam's own repo...)? Is the fingerprint above the correct one (and for that matter, where is the GPG Key's Fingerprint recorded on the oVirt Website so that we can check compliance ourselves)?
Anyway, thought I'd let people know (further details can be provide upon request)
Cheers
Dulux-Oz _______________________________________________ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-leave@ovirt.org Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/WILIDSO6CMHHJL...
-- Att, Jorge Visentini +55 55 98432-9868
<https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=emailclient> Virus-free.www.avast.com <https://www.avast.com/sig-email?utm_medium=email&utm_source=link&utm_campaign=sig-email&utm_content=emailclient> <#m_-321625164339204607_m_3968352809059148212_DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2>
_______________________________________________ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-leave@ovirt.org Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/QP52KSI67LRMVE...
_______________________________________________ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-leave@ovirt.org Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/GWLT4VZBP4DOOA...

I just ran into the same issue when trying to upgrade an existing oVirt Node host from 4.5.4 to 4.5.5. My problem seems to be with the package ovirt-node-ng-image-update. I made sure to to download the latest package from the mirror by running dnf clean all before upgrading. Can you resign this as well or is there a problem with the mirror? DNF transaction: [root@server ~]# dnf update --downloadonly -y Last metadata expiration check: 0:14:39 ago on Fri 23 Feb 2024 04:04:26 PM CET. Dependencies resolved. ======================================================================================================================== Package Architecture Version Repository Size ======================================================================================================================== Upgrading: ovirt-node-ng-image-update noarch 4.5.5-1.el8 ovirt-45-upstream 1.3 G replacing ovirt-node-ng-image-update-placeholder.noarch 4.5.4-1.el8 Transaction Summary ======================================================================================================================== Upgrade 1 Package Total size: 1.3 G DNF will only download packages for the transaction. Downloading Packages: [SKIPPED] ovirt-node-ng-image-update-4.5.5-1.el8.noarch.rpm: Already downloaded oVirt upstream for CentOS Stream 8 - oVirt 4.5 2.8 MB/s | 2.9 kB 00:00 GPG key at file:///etc/pki/rpm-gpg/RPM-GPG-KEY-oVirt-4.5 (0xFE590CB7) is already installed The GPG keys listed for the "oVirt upstream for CentOS Stream 8 - oVirt 4.5" repository are already installed but they are not correct for this package. Check that the correct key URLs are configured for this repository.. Failing package is: ovirt-node-ng-image-update-4.5.5-1.el8.noarch GPG Keys are configured as: file:///etc/pki/rpm-gpg/RPM-GPG-KEY-oVirt-4.5 The downloaded packages were saved in cache until the next successful transaction. You can remove cached packages by executing 'dnf clean packages'. Error: GPG check FAILED Package data: # less /var/cache/dnf/ovirt-45-upstream-62781357e04a3932/packages/ovirt-node-ng-image-update-4.5.5-1.el8.noarch.rpm | grep -E 'Signature|Build' Signature : RSA/SHA256, Sun 14 Jan 2024 12:46:53 PM CET, Key ID 44e475cb24901d0c Build Date : Thu 30 Nov 2023 04:23:38 PM CET Build Host : 579f68922225

Some more context: # rpm --checksig --verbose /var/cache/dnf/ovirt-45-upstream-62781357e04a3932/packages/ovirt-node-ng-image-update-4.5.5-1.el8.noarch.rpm /var/cache/dnf/ovirt-45-upstream-62781357e04a3932/packages/ovirt-node-ng-image-update-4.5.5-1.el8.noarch.rpm: Header V4 RSA/SHA256 Signature, key ID 24901d0c: NOKEY Header SHA256 digest: OK Header SHA1 digest: OK Payload SHA256 digest: OK V4 RSA/SHA256 Signature, key ID 24901d0c: NOKEY MD5 digest: OK

Hi Jonas, New packages are currently being signed with the new 4096 bit key, which can be downloaded from: https://resources.ovirt.org/pub/keys/RPM-GPG-ovirt-v4 It was supplied automatically for EL9/C9S releases, but missed the EL8/C8S release packages. Can you please try to import the new key manually and check if it helps? Thanks in advance, On Sat, Feb 24, 2024 at 11:35 AM Jonas <jonas@rabe.ch> wrote:
Some more context:
# rpm --checksig --verbose /var/cache/dnf/ovirt-45-upstream-62781357e04a3932/packages/ovirt-node-ng-image-update-4.5.5-1.el8.noarch.rpm
/var/cache/dnf/ovirt-45-upstream-62781357e04a3932/packages/ovirt-node-ng-image-update-4.5.5-1.el8.noarch.rpm: Header V4 RSA/SHA256 Signature, key ID 24901d0c: NOKEY Header SHA256 digest: OK Header SHA1 digest: OK Payload SHA256 digest: OK V4 RSA/SHA256 Signature, key ID 24901d0c: NOKEY MD5 digest: OK _______________________________________________ Users mailing list -- users@ovirt.org To unsubscribe send an email to users-leave@ovirt.org Privacy Statement: https://www.ovirt.org/privacy-policy.html oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/A2KA6MLNPUJHZD...
-- LEV VEYDE SENIOR SOFTWARE ENGINEER, RHCE | RHCVA | MCITP Red Hat Israel <https://www.redhat.com/> lev@redhat.com | lveyde@redhat.com <https://red.ht/sig> TRIED. TESTED. TRUSTED. <https://redhat.com/trusted>

Hi Lev Thanks a lot, I can confirm that the signature now correctly verifies with the new key. Thanks also for updating the oVirt site with the new key! Regards Jonas On 26.02.24 15:45, Lev Veyde wrote:
Hi Jonas,
New packages are currently being signed with the new 4096 bit key, which can be downloaded from: https://resources.ovirt.org/pub/keys/RPM-GPG-ovirt-v4 <https://resources.ovirt.org/pub/keys/RPM-GPG-ovirt-v4>
It was supplied automatically for EL9/C9S releases, but missed the EL8/C8S release packages.
Can you please try to import the new key manually and check if it helps?
Thanks in advance,
On Sat, Feb 24, 2024 at 11:35 AM Jonas <jonas@rabe.ch <mailto:jonas@rabe.ch>> wrote:
Some more context:
# rpm --checksig --verbose /var/cache/dnf/ovirt-45-upstream-62781357e04a3932/packages/ovirt-node-ng-image-update-4.5.5-1.el8.noarch.rpm
/var/cache/dnf/ovirt-45-upstream-62781357e04a3932/packages/ovirt-node-ng-image-update-4.5.5-1.el8.noarch.rpm: Header V4 RSA/SHA256 Signature, key ID 24901d0c: NOKEY Header SHA256 digest: OK Header SHA1 digest: OK Payload SHA256 digest: OK V4 RSA/SHA256 Signature, key ID 24901d0c: NOKEY MD5 digest: OK _______________________________________________ Users mailing list -- users@ovirt.org <mailto:users@ovirt.org> To unsubscribe send an email to users-leave@ovirt.org <mailto:users-leave@ovirt.org> Privacy Statement: https://www.ovirt.org/privacy-policy.html <https://www.ovirt.org/privacy-policy.html> oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ <https://www.ovirt.org/community/about/community-guidelines/> List Archives: https://lists.ovirt.org/archives/list/users@ovirt.org/message/A2KA6MLNPUJHZD... <https://lists.ovirt.org/archives/list/users@ovirt.org/message/A2KA6MLNPUJHZDLZ6NJTBT4IZT33HADS/>
--
LEV VEYDE
SENIOR SOFTWARE ENGINEER, RHCE | RHCVA | MCITP
Red Hat Israel
lev@redhat.com <mailto:lev@redhat.com> | lveyde@redhat.com <mailto:lveyde@redhat.com>
<https://red.ht/sig> TRIED. TESTED. TRUSTED. <https://redhat.com/trusted>

Hi Jonas, You're welcome, and thanks for letting us know. Thanks in advance, On Mon, Feb 26, 2024 at 6:44 PM Jonas <jonas@rabe.ch> wrote:
Hi Lev
Thanks a lot, I can confirm that the signature now correctly verifies with the new key. Thanks also for updating the oVirt site with the new key!
Regards Jonas
On 26.02.24 15:45, Lev Veyde wrote:
Hi Jonas,
New packages are currently being signed with the new 4096 bit key, which can be downloaded from: https://resources.ovirt.org/pub/keys/RPM-GPG-ovirt-v4 <https://resources.ovirt.org/pub/keys/RPM-GPG-ovirt-v4>
It was supplied automatically for EL9/C9S releases, but missed the EL8/C8S release packages.
Can you please try to import the new key manually and check if it helps?
Thanks in advance,
On Sat, Feb 24, 2024 at 11:35 AM Jonas <jonas@rabe.ch <mailto:jonas@rabe.ch>> wrote:
Some more context:
# rpm --checksig --verbose
/var/cache/dnf/ovirt-45-upstream-62781357e04a3932/packages/ovirt-node-ng-image-update-4.5.5-1.el8.noarch.rpm
/var/cache/dnf/ovirt-45-upstream-62781357e04a3932/packages/ovirt-node-ng-image-update-4.5.5-1.el8.noarch.rpm:
Header V4 RSA/SHA256 Signature, key ID 24901d0c: NOKEY Header SHA256 digest: OK Header SHA1 digest: OK Payload SHA256 digest: OK V4 RSA/SHA256 Signature, key ID 24901d0c: NOKEY MD5 digest: OK _______________________________________________ Users mailing list -- users@ovirt.org <mailto:users@ovirt.org> To unsubscribe send an email to users-leave@ovirt.org <mailto:users-leave@ovirt.org> Privacy Statement: https://www.ovirt.org/privacy-policy.html <https://www.ovirt.org/privacy-policy.html> oVirt Code of Conduct: https://www.ovirt.org/community/about/community-guidelines/ <https://www.ovirt.org/community/about/community-guidelines/> List Archives:
https://lists.ovirt.org/archives/list/users@ovirt.org/message/A2KA6MLNPUJHZD... < https://lists.ovirt.org/archives/list/users@ovirt.org/message/A2KA6MLNPUJHZD...
--
LEV VEYDE
SENIOR SOFTWARE ENGINEER, RHCE | RHCVA | MCITP
Red Hat Israel
lev@redhat.com <mailto:lev@redhat.com> | lveyde@redhat.com <mailto:lveyde@redhat.com>
<https://red.ht/sig> TRIED. TESTED. TRUSTED. <https://redhat.com/trusted>
-- LEV VEYDE SENIOR SOFTWARE ENGINEER, RHCE | RHCVA | MCITP Red Hat Israel <https://www.redhat.com/> lev@redhat.com | lveyde@redhat.com <https://red.ht/sig> TRIED. TESTED. TRUSTED. <https://redhat.com/trusted>

So I just re-ran the `dnf install ovirt-engine-appliance` on a fresh box and everything went AOK - looks like the solution provided is correct - thanks you. (FTR: i wasn't complaining per say; I was simply trying to point out there there was a (potential) issue which people might like to look into / resolve. I know I welcome those types of reports when I f-up my apps. :-) )

This has now been resolved with a fix by the oVirt devs. See also: https://lists.ovirt.org/archives/list/users@ovirt.org/thread/EXVHQ37VCCFQDUZ...
participants (7)
-
duluxoz
-
Jirka Simon
-
Jonas
-
Jorge Visentini
-
Lev Veyde
-
Matthew J Black
-
Matthew J Black