Uploaded image for project: 'RHEL Conversions'
  1. RHEL Conversions
  2. RHELC-322

Import SHA2 RPM GPG key on RHEL 9

XMLWordPrintable

    • 3

      RHEL 9 is moving away from SHA1. When converting to RHEL 9 we need to make sure a correct package signing GPG key is imported. And that no SHA1-signed packages are installed prior to the conversion as it might cause issues when using dnf (analysis needed - what kind of issues?).

      Acceptance criteria:

      • Convert2RHEL is shipped with the new SHA2 rpm gpg key
      • the SHA2 key is imported through the rpm command during the conversion to RHEL 9 instead of the old SHA1 key
      • the conversion is inhibited when SHA1-signed packages are detected

      Related: https://bugzilla.redhat.com/show_bug.cgi?id=2058497#c26

              mbocek@redhat.com Michal Bocek
              mbocek@redhat.com Michal Bocek
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: