Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-143043

rpm-ostree compose rootfs failed to verify gpg signature for pacakges

Linking RHIVOS CVEs to...Migration: Automation ...Sync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Major Major
    • None
    • rhel-10.1.z
    • rpm-ostree
    • None
    • None
    • Important
    • rhel-image-mode
    • None
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None
    • None
    • Unspecified
    • Unspecified
    • Unspecified
    • None

      What were you trying to do that didn't work?

      rpm-ostree compose rootfs

      What is the impact of this issue to you?

      Failed to build bootc base image from scratch for production rhel-bootc:10.1 image.

      Please provide the package NVR for which the bug is seen:

      rpm-ostree-2025.11-1.el10_1.x86_64

      How reproducible is this bug?:

      100%

      Steps to reproduce

      1. Prepare a rhel10.1 host and subscribed with rhsm
      2. sudo rpm-ostree compose rootfs --source-root=/ /home/wshi/bifrost/src/rhel-bootc/standard.yaml /home/wshi/tmp
      1.  

      Expected results

      Build successful

      Actual results

      ...
      ...
      ...
      Will download: 480 packages (664.0 MB)
      ⠙ Downloading from 'rhel-10-for-x86_64-baseos-rpms'  90% [██████████████████░░] (27s)
      ⠒ Downloading from 'rhel-10-for-x86_64-baseos-rpms'  92% [██████████████████░░] (20s)
      Downloading from 'rhel-10-for-x86_64-baseos-rpms'... done
      Downloading from 'rhel-10-for-x86_64-appstream-rpms'... done
      ⠚ Importing packages 381/480 [███████████████░░░░░] (1s)
      error: Installing packages: importing RPMs: package gnupg2-2.4.5-3.el10_1.x86_64 cannot be verified and repo rhel-10-for-x86_64-baseos-rpms is GPG enabled: /proc/self/f
      d/16/cache/repomd/rhel-10-for-x86_64-baseos-rpms-10.1-x86_64/packages/gnupg2-2.4.5-3.el10_1.x86_64.rpm could not be verified.
      /proc/self/fd/16/cache/repomd/rhel-10-for-x86_64-baseos-rpms-10.1-x86_64/packages/gnupg2-2.4.5-3.el10_1.x86_64.rpm:  digest:  SIGNATURE:  NOT OK
      error: Executing compose install: ExitStatus(unix_wait_status(256)) 

      Additional info

      $ rpm -qi gnupg2
      Name        : gnupg2
      Version     : 2.4.5
      Release     : 3.el10_1
      Architecture: x86_64
      Install Date: Wed Jan 21 00:10:53 2026
      Group       : Unspecified
      Size        : 9986557
      License     : CC0-1.0 AND GPL-2.0-or-later AND GPL-3.0-or-later AND LGPL-2.1-or-later AND LGPL-3.0-or-later AND (BSD-3-Clause OR LGPL-3.0-or-later OR GPL-2.0-or-later) AND CC-BY-4.0 AND MIT
      Signature   :
                    RSA/SHA256, Wed Jan 14 00:45:48 2026, Key ID 199e2f91fd431d51
                    ML-DSA-87+Ed448/SHA512, Wed Jan 14 00:45:49 2026, Key ID fcd355b305707a62

              rhn-support-jmarrero Joseph Marrero Corchado
              wshi@redhat.com Wei Shi
              Joseph Marrero Corchado Joseph Marrero Corchado
              Xiaofeng Wang Xiaofeng Wang
              Votes:
              0 Vote for this issue
              Watchers:
              7 Start watching this issue

                Created:
                Updated: