-
Task
-
Resolution: Won't Do
-
Normal
-
None
-
False
-
False
-
3
RHEL 9 is moving away from SHA1. When converting to RHEL 9 we need to make sure a correct package signing GPG key is imported. And that no SHA1-signed packages are installed prior to the conversion as it might cause issues when using dnf (analysis needed - what kind of issues?).
Acceptance criteria:
- Convert2RHEL is shipped with the new SHA2 rpm gpg key
- the SHA2 key is imported through the rpm command during the conversion to RHEL 9 instead of the old SHA1 key
- the conversion is inhibited when SHA1-signed packages are detected
Related: https://bugzilla.redhat.com/show_bug.cgi?id=2058497#c26
- is related to
-
RHELC-1756 Do not bundle RHEL 5 GPG key
- Release Pending