[Rpm-maint] [rpm-software-management/rpm] urpmi --no-verify is broken by rpm checking on its own with rpm-sequoia (Discussion #3203)
Bruno Cornec
notifications at github.com
Mon Jan 20 10:41:52 UTC 2025
@soig, I just found this threa as I was looking for an error in updating my mageia cauldron docker container image :-(
After doing urpmi.update -a
and trying to install build deps for the tellico package, I had the following:
``
urpmi SPECS/tellico.spec
To satisfy dependencies, the following packages are going to be installed:
Package Version Release Arch
(medium "Core Release (mga1)")
binutils 2.43.1 2.mga10 x86_64
bm 3.9 1.mga10 noarch
cmake-rpm-macros 9 9.mga9 noarch
elfutils 0.192 4.mga10 x86_64
gcc 14.2.0 2.mga10 x86_64
gcc-c++ 14.2.0 2.mga10 x86_64
gcc-cpp 14.2.0 2.mga10 x86_64
gdb-headless 15.2 1.mga10 x86_64
gdb-minimal 15.2 1.mga10 x86_64
glibc 2.40 1.mga10 x86_64
glibc-devel 2.40 1.mga10 x86_64
gobject-introspection 1.82.0 1.mga10 x86_64
lib64asm1 0.192 4.mga10 x86_64
lib64debuginfod1 0.192 4.mga10 x86_64
lib64dw1 0.192 4.mga10 x86_64
lib64elf1 0.192 4.mga10 x86_64
lib64mpdec4 4.0.0 1.mga10 x86_64
lib64nsl3 2.0.1 1.mga10 x86_64
lib64openblas-serial0 0.3.28 1.mga10 x86_64 (recommended)
lib64openssl3 3.3.2 2.mga10 x86_64
lib64pcre2posix3 10.44 1.mga10 x86_64
lib64python3.12 3.12.8 1.mga10 x86_64
lib64python3.12-stdlib 3.12.8 1.mga10 x86_64
lib64rpm10 4.20.0 1.mga10 x86_64
lib64rpmbuild10 4.20.0 1.mga10 x86_64
lib64rpmsign10 4.20.0 1.mga10 x86_64
lib64xcrypt-devel 4.4.37 1.mga10 x86_64
lib64xcrypt1 4.4.37 1.mga10 x86_64
libgfortran5 14.2.0 2.mga10 x86_64 (recommended)
libgomp-devel 14.2.0 2.mga10 x86_64
libgomp1 14.2.0 2.mga10 x86_64
libquadmath0 14.2.0 2.mga10 x86_64 (recommended)
libstdc++-devel 14.2.0 2.mga10 x86_64
libstdc++6 14.2.0 2.mga10 x86_64
mgarepo 1.14.6 2.mga10 noarch
openblas 0.3.28 1.mga10 x86_64 (recommended)
openssl 3.3.2 2.mga10 x86_64
pcre2-tools 10.44 1.mga10 x86_64
perl 5.40.0 3.mga10 x86_64
perl-File-Sync 0.110.0 39.mga10 x86_64
perl-Filesys-Df 0.920.0 40.mga10 x86_64
perl-List-MoreUtils-XS 0.430 12.mga10 x86_64
perl-Locale-gettext 1.70.0 22.mga10 x86_64
perl-URPM 5.225 4.mga10 x86_64
perl-XML-LibXML 2.21.0 8.mga10 x86_64
perl-base 5.40.0 3.mga10 x86_64
pyproject-rpm-macros 1.16.3 1.mga10 noarch
pyproject-srpm-macros 1.16.3 1.mga10 noarch
python3 3.12.8 1.mga10 x86_64
python3-dateutil 2.9.0.post0 1.mga10 noarch (recommended)
python3-httplib2 0.22.0 1.mga10 noarch
python3-numpy 2.1.3 3.mga10 x86_64 (recommended)
python3-packaging 24.0 1.mga10 noarch
python3-pandas 2.2.2 2.mga10 x86_64 (recommended)
python3-pip 24.3.1 1.mga10 noarch
python3-pygments 2.17.2 1.mga10 noarch
python3-pyparsing 3.1.2 1.mga10 noarch
python3-pytz 2024.1 1.mga10 noarch (recommended)
python3-rpm 4.20.0 1.mga10 x86_64
python3-setuptools 75.6.0 1.mga10 noarch
python3-six 1.16.0 6.mga10 noarch
python3-tqdm 4.67.1 2.mga10 noarch
python3-tzdata 2023.3 2.mga10 noarch (recommended)
python3-wheel 0.43.0 1.mga10 noarch
rpm 4.20.0 1.mga10 x86_64
rpm-build 4.20.0 1.mga10 x86_64
rpm-mageia-setup 2.82 1.mga10 x86_64
rpm-mageia-setup-build 2.82 1.mga10 x86_64
rpm-sequoia 1.7.0 1.mga10 x86_64
rust-srpm-macros 26.3 2.mga10 noarch
260MB of additional disk space will be used.
158MB of packages will be retrieved.
Proceed with the installation of the 70 packages? (Y/n) y
[... download phase ....]
installing lib64rpmbuild10-4.20.0-1.mga10.x86_64.rpm lib64python3.12-stdlib-3.12.8-1.mga10.x86_64.rpm perl-XML-LibXML-2.21.0-8.mga10.x86_64.rpm python3-httplib2-0.22.0-1.mga10.noarch.rpm libgomp1-14.2.0-2.mga10.x86_64.rpm rpm-4.20.0-1.mga10.x86_64.rpm python3-packaging-24.0-1.mga10.noarch.rpm python3-tzdata-2023.3-2.mga10.noarch.rpm python3-pytz-2024.1-1.mga10.noarch.rpm pyproject-srpm-macros-1.16.3-1.mga10.noarch.rpm lib64xcrypt-devel-4.4.37-1.mga10.x86_64.rpm python3-dateutil-2.9.0.post0-1.mga10.noarch.rpm pcre2-tools-10.44-1.mga10.x86_64.rpm rpm-mageia-setup-build-2.82-1.mga10.x86_64.rpm python3-wheel-0.43.0-1.mga10.noarch.rpm mgarepo-1.14.6-2.mga10.noarch.rpm lib64rpmsign10-4.20.0-1.mga10.x86_64.rpm lib64rpm10-4.20.0-1.mga10.x86_64.rpm perl-base-5.40.0-3.mga10.x86_64.rpm lib64dw1-0.192-4.mga10.x86_64.rpm libgomp-devel-14.2.0-2.mga10.x86_64.rpm gcc-14.2.0-2.mga10.x86_64.rpm lib64debuginfod1-0.192-4.mga10.x86_64.rpm cmake-rpm-macros-9-9.mga9.noarch.rpm openssl-3.3.2-2.mga10.x86_64.rpm libgfortran5-14.2.0-2.mga10.x86_64.rpm python3-pandas-2.2.2-2.mga10.x86_64.rpm glibc-devel-2.40-1.mga10.x86_64.rpm binutils-2.43.1-2.mga10.x86_64.rpm python3-tqdm-4.67.1-2.mga10.noarch.rpm rust-srpm-macros-26.3-2.mga10.noarch.rpm python3-pygments-2.17.2-1.mga10.noarch.rpm lib64openssl3-3.3.2-2.mga10.x86_64.rpm perl-URPM-5.225-4.mga10.x86_64.rpm gcc-c++-14.2.0-2.mga10.x86_64.rpm perl-List-MoreUtils-XS-0.430-12.mga10.x86_64.rpm pyproject-rpm-macros-1.16.3-1.mga10.noarch.rpm perl-Filesys-Df-0.920.0-40.mga10.x86_64.rpm lib64mpdec4-4.0.0-1.mga10.x86_64.rpm elfutils-0.192-4.mga10.x86_64.rpm rpm-mageia-setup-2.82-1.mga10.x86_64.rpm python3-six-1.16.0-6.mga10.noarch.rpm bm-3.9-1.mga10.noarch.rpm lib64xcrypt1-4.4.37-1.mga10.x86_64.rpm glibc-2.40-1.mga10.x86_64.rpm python3-rpm-4.20.0-1.mga10.x86_64.rpm python3-numpy-2.1.3-3.mga10.x86_64.rpm openblas-0.3.28-1.mga10.x86_64.rpm python3-pip-24.3.1-1.mga10.noarch.rpm rpm-build-4.20.0-1.mga10.x86_64.rpm lib64pcre2posix3-10.44-1.mga10.x86_64.rpm perl-5.40.0-3.mga10.x86_64.rpm python3-pyparsing-3.1.2-1.mga10.noarch.rpm lib64python3.12-3.12.8-1.mga10.x86_64.rpm python3-setuptools-75.6.0-1.mga10.noarch.rpm perl-Locale-gettext-1.70.0-22.mga10.x86_64.rpm python3-3.12.8-1.mga10.x86_64.rpm perl-File-Sync-0.110.0-39.mga10.x86_64.rpm rpm-sequoia-1.7.0-1.mga10.x86_64.rpm gdb-minimal-15.2-1.mga10.x86_64.rpm libquadmath0-14.2.0-2.mga10.x86_64.rpm lib64asm1-0.192-4.mga10.x86_64.rpm lib64nsl3-2.0.1-1.mga10.x86_64.rpm lib64openblas-serial0-0.3.28-1.mga10.x86_64.rpm gcc-cpp-14.2.0-2.mga10.x86_64.rpm libstdc++6-14.2.0-2.mga10.x86_64.rpm gobject-introspection-1.82.0-1.mga10.x86_64.rpm lib64elf1-0.192-4.mga10.x86_64.rpm libstdc++-devel-14.2.0-2.mga10.x86_64.rpm gdb-headless-15.2-1.mga10.x86_64.rpm from /var/cache/urpmi/rpms
Preparing... #############################################
1/70: glibc #############################################
System has not been booted with systemd as init system (PID 1). Can't operate.
Failed to connect to bus: Host is down
2/70: lib64xcrypt1 #############################################
3/70: perl-base #############################################
4/70: lib64elf1 #############################################
5/70: lib64dw1 #############################################
6/70: lib64debuginfod1 #############################################
7/70: lib64openssl3 #############################################
8/70: perl #############################################
9/70: rpm-mageia-setup #############################################
10/70: rpm-sequoia #############################################
11/70: lib64rpm10 #############################################
12/70: rpm #############################################
13/70: lib64rpmsign10 #############################################
14/70: lib64asm1 #############################################
15/70: lib64xcrypt-devel #############################################
16/70: glibc-devel #############################################
17/70: lib64mpdec4 #############################################
18/70: lib64pcre2posix3 #############################################
19/70: pcre2-tools #############################################
20/70: lib64nsl3 #############################################
21/70: python3 #############################################
22/70: lib64python3.12-stdlib
#############################################
23/70: lib64python3.12 #############################################
24/70: python3-setuptools #############################################
25/70: gobject-introspection #############################################
26/70: python3-packaging #############################################
27/70: python3-tzdata #############################################
28/70: python3-pytz #############################################
29/70: python3-wheel #############################################
30/70: python3-six #############################################
31/70: python3-dateutil #############################################
32/70: python3-pip #############################################
33/70: python3-pyparsing #############################################
34/70: python3-httplib2 #############################################
35/70: gcc-cpp #############################################
36/70: openblas #############################################
37/70: rust-srpm-macros #############################################
38/70: libstdc++6 #############################################
39/70: binutils #############################################
40/70: libstdc++-devel #############################################
41/70: gcc #############################################
42/70: libgomp1 #############################################
43/70: lib64rpmbuild10 #############################################
44/70: python3-rpm #############################################
45/70: gdb-headless #############################################
46/70: libgomp-devel #############################################
47/70: gcc-c++ #############################################
48/70: elfutils #############################################
49/70: gdb-minimal #############################################
50/70: pyproject-srpm-macros #############################################
51/70: cmake-rpm-macros #############################################
52/70: rpm-mageia-setup-build
#############################################
53/70: rpm-build #############################################
54/70: pyproject-rpm-macros #############################################
55/70: libquadmath0 #############################################
56/70: bm #############################################
57/70: perl-URPM #############################################
58/70: python3-pygments #############################################
59/70: perl-List-MoreUtils-XS
#############################################
60/70: openssl #############################################
61/70: perl-XML-LibXML #############################################
Warning: program compiled against libxml 212 using older 209
Warning: XML::LibXML compiled against libxml2 21209, but runtime libxml2 is older 20914
62/70: perl-Filesys-Df #############################################
63/70: perl-Locale-gettext #############################################
64/70: perl-File-Sync #############################################
65/70: libgfortran5 #############################################
66/70: lib64openblas-serial0 #############################################
67/70: python3-numpy #############################################
68/70: python3-pandas #############################################
69/70: python3-tqdm #############################################
70/70: mgarepo #############################################
[ ... removal phase ...]
You should restart your computer for glibc
restarting urpmi
defaulting to --buildrequires
[ ... tons of packages to install ...]
2.8GB of additional disk space will be used.
714MB of packages will be retrieved.
Proceed with the installation of the 1333 packages? (Y/n) y
[ ... download phase ...]
error: Verifying a signature using certificate 00EDB89585B012A8916F0DF8B742FA8B80420F66 (Mageia Packages <packages at mageia.org>):
1. Certificate B742FA8B80420F66 invalid: policy violation
because: No binding signature at time 2025-01-15T18:36:25Z
because: Policy rejected non-revocation signature (PositiveCertification) requiring second pre-image resistance
because: SHA1 is not considered secure since 2023-02-01T00:00:00Z
2. Certificate B742FA8B80420F66 invalid: policy violation
because: No binding signature at time 2025-01-20T10:30:04Z
because: Policy rejected non-revocation signature (PositiveCertification) requiring second pre-image resistance
because: SHA1 is not considered secure since 2023-02-01T00:00:00Z
warning: /var/cache/urpmi/rpms/lib64mount1-2.40.4-1.mga10.x86_64.rpm: Header V4 RSA/SHA256 Signature, key ID 80420f66: NOTTRUSTED
error: Verifying a signature using certificate 00EDB89585B012A8916F0DF8B742FA8B80420F66 (Mageia Packages <packages at mageia.org>):
1. Certificate B742FA8B80420F66 invalid: policy violation
because: No binding signature at time 2022-03-18T20:37:16Z
because: Policy rejected non-revocation signature (PositiveCertification) requiring second pre-image resistance
because: SHA1 is not considered secure since 2023-02-01T00:00:00Z
2. Certificate B742FA8B80420F66 invalid: policy violation
because: No binding signature at time 2025-01-20T10:30:04Z
because: Policy rejected non-revocation signature (PositiveCertification) requiring second pre-image resistance
because: SHA1 is not considered secure since 2023-02-01T00:00:00Z
going on for all the remaining packages.
Have you found a workaround for this ?
--
Reply to this email directly or view it on GitHub:
https://github.com/rpm-software-management/rpm/discussions/3203#discussioncomment-11889083
You are receiving this because you are subscribed to this thread.
Message ID: <rpm-software-management/rpm/repo-discussions/3203/comments/11889083 at github.com>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.rpm.org/pipermail/rpm-maint/attachments/20250120/f3bac409/attachment-0001.htm>
More information about the Rpm-maint
mailing list