Bug 34918 - Mageia 9: Update expiring RPM-GPG-KEY-Mageia
Summary: Mageia 9: Update expiring RPM-GPG-KEY-Mageia
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: RPM Packages (show other bugs)
Version: 9
Hardware: All Linux
Priority: High major
Target Milestone: ---
Assignee: QA Team
QA Contact:
URL:
Whiteboard: MGA9-64-OK MGA9-32-OK
Keywords: IN_ERRATA9, IN_RELEASENOTES10, advisory, validated_update
Depends on:
Blocks: 34920
  Show dependency treegraph
 
Reported: 2025-12-29 11:39 CET by Jani Välimaa
Modified: 2025-12-31 02:20 CET (History)
5 users (show)

See Also:
Source RPM: mageia-repos-9-4.mga9, distribution-gpg-keys-1.89-1.mga9
CVE:
Status comment:


Attachments

Description Jani Välimaa 2025-12-29 11:39:29 CET
Current key expires 2025-12-31.

$ gpg2 --show-key /etc/pki/rpm-gpg/RPM-GPG-KEY-Mageia
pub   rsa4096 2011-02-07 [SCEA] [expires: 2025-12-31]
      00EDB89585B012A8916F0DF8B742FA8B80420F66
uid                      Mageia Packages <packages@mageia.org>
Comment 1 Jani Välimaa 2025-12-29 12:02:39 CET
mageia-repos-9-4.1.mga9 in core/updates_testing should fix the issue.

$ rpm -qa mageia-repos-keys
mageia-repos-keys-9-4.1.mga9

$ gpg2 --show-key /etc/pki/rpm-gpg/RPM-GPG-KEY-Mageia
pub   rsa4096 2011-02-07 [SCEA] [expires: 2029-12-31]
      00EDB89585B012A8916F0DF8B742FA8B80420F66
uid                      Mageia Packages <packages@mageia.org>

Assignee: bugsquad => qa-bugs

Comment 2 Jani Välimaa 2025-12-29 12:04:43 CET Comment hidden (obsolete)
Comment 3 Morgan Leijström 2025-12-29 15:07:07 CET
Thanks for spotting!
- and fixing immediately!

Selecting updates in drakrpm brought the three packages except the cauldron one.

$ rpm -qa mageia-repos-keys
mageia-repos-keys-9-4.1.mga9

$ gpg2 --show-key /etc/pki/rpm-gpg/RPM-GPG-KEY-Mageia
pub   rsa4096 2011-02-07 [SCEA] [går ut: 2029-12-31]
      00EDB89585B012A8916F0DF8B742FA8B80420F66
uid                      Mageia Packages <packages@mageia.org>

Test OK also: I could remove all configured repos, and add a fresh set using urpmi.addmedia


I wonder, to facilitate upgrading to mga10, an idea would be to make that one 
install as a dependency, would that solve the issue?
(Note this is not my cup of tea...)

Assignee: qa-bugs => bugsquad
CC: (none) => fri, marja11, sysadmin-bugs
Priority: Normal => High

Comment 4 Jani Välimaa 2025-12-29 15:18:24 CET
This is a separate thing than 'broken' RPM signing key that prevents upgrading from mga9 to mga10 with urpmi without manual interaction. /etc/pki/rpm-gpg/RPM-GPG-KEY-Mageia is only used with tools like mock.
Jani Välimaa 2025-12-29 15:41:07 CET

Blocks: (none) => 34920

Comment 5 Jani Välimaa 2025-12-29 16:41:26 CET
(In reply to Jani Välimaa from comment #4)
> This is a separate thing than 'broken' RPM signing key that prevents
> upgrading from mga9 to mga10 with urpmi without manual interaction.
> /etc/pki/rpm-gpg/RPM-GPG-KEY-Mageia is only used with tools like mock.

Bug 34920 is more for tracking that one.
Jani Välimaa 2025-12-29 16:58:00 CET

Assignee: bugsquad => qa-bugs

Comment 6 Thomas Andrews 2025-12-29 18:47:18 CET
Before the update:

[tom@localhost ~]$ rpm -qa mageia-repos-keys
mageia-repos-keys-9-4.mga9
[tom@localhost ~]$ gpg2 --show-key /etc/pki/rpm-gpg/RPM-GPG-KEY-Mageia
pub   rsa4096 2011-02-07 [SCEA] [expires: 2025-12-31]
      00EDB89585B012A8916F0DF8B742FA8B80420F66
uid                      Mageia Packages <packages@mageia.org>

After the update:

[tom@localhost ~]$ rpm -qa mageia-repos-keys
mageia-repos-keys-9-4.1.mga9
[tom@localhost ~]$ gpg2 --show-key /etc/pki/rpm-gpg/RPM-GPG-KEY-Mageia
pub   rsa4096 2011-02-07 [SCEA] [expires: 2029-12-31]
      00EDB89585B012A8916F0DF8B742FA8B80420F66
uid                      Mageia Packages <packages@mageia.org>

Looks good here on 64-bit.

CC: (none) => andrewsfarm
Whiteboard: (none) => MGA9-64-OK

Comment 7 Thomas Andrews 2025-12-29 19:02:20 CET
Also good for i586.

Validating.

Keywords: (none) => validated_update
Whiteboard: MGA9-64-OK => MGA9-64-OK MGA9-32-OK

Comment 8 Morgan Leijström 2025-12-29 19:14:01 CET
Thanks for the quick fixing Jani!
And info.

/ Regarding flags in this bug I happened to set them by accident in comment 3 because I initially was trying responding to comment 0 but that did never get posted so flags was set for another circuntance...  Bugzilla have been really slow today, Forum and Wiki seemed to be offline and mail list sends me double mails... /
Comment 9 PC LX 2025-12-29 19:30:29 CET
Installed and tested without issues.



System: Mageia 9, x86_64, AMD Ryzen 5 5600G with Radeon Graphics



$ uname -a
Linux jupiter 6.6.116-desktop-1.mga9 #1 SMP PREEMPT_DYNAMIC Mon Nov  3 15:35:03 UTC 2025 x86_64 GNU/Linux
$ rpm -qa | grep mageia-repos-
mageia-repos-keys-9-4.1.mga9
mageia-repos-pkgprefs-9-4.1.mga9
mageia-repos-9-4.1.mga9
$ gpg2 --show-key /etc/pki/rpm-gpg/RPM-GPG-KEY-Mageia
pub   rsa4096 2011-02-07 [SCEA] [expires: 2029-12-31]
      00EDB89585B012A8916F0DF8B742FA8B80420F66
uid                      Mageia Packages <packages@mageia.org>

CC: (none) => mageia
Keywords: validated_update => (none)
Whiteboard: MGA9-64-OK MGA9-32-OK => MGA9-64-OK

katnatek 2025-12-29 19:46:21 CET

Keywords: (none) => advisory

Comment 10 Thomas Andrews 2025-12-30 15:42:53 CET
HP Pavilion 15 laptop,AMD A8-4555, MGA9-64 Plasma.

No installation issues. After the update:

[tom@localhost ~]$ rpm -qa mageia-repos-keys
mageia-repos-keys-9-4.1.mga9
[tom@localhost ~]$ gpg2 --show-key /etc/pki/rpm-gpg/RPM-GPG-KEY-Mageia
gpg: WARNING: unsafe permissions on homedir '/home/tom/.gnupg'
pub   rsa4096 2011-02-07 [SCEA] [expires: 2029-12-31]
      00EDB89585B012A8916F0DF8B742FA8B80420F66
uid                      Mageia Packages <packages@mageia.org>


Not sure what it doesn't like about the permissions in the home directory, but it seems to be OK, anyway.
Comment 11 katnatek 2025-12-30 18:04:50 CET
Edited advisory to add info about mock
Comment 12 Thomas Andrews 2025-12-30 18:14:04 CET
Looks like this can go, then.

Validating.

Whiteboard: MGA9-64-OK => MGA9-64-OK MGA9-32-OK
Keywords: (none) => validated_update

Comment 13 Jani Välimaa 2025-12-30 18:16:10 CET
Actually mock seems to be using /usr/share/distribution-gpg-keys/mageia/RPM-GPG-KEY-Mageia. It's dnf that is using /etc/pki/rpm-gpg/RPM-GPG-KEY-Mageia.

So I'll need to update also distribution-gpg-keys for mga9.
Jani Välimaa 2025-12-30 18:16:26 CET

Keywords: validated_update => (none)

Comment 14 Jani Välimaa 2025-12-30 18:53:29 CET
Updated distribution-gpg-keys-1.89-1.1.mga9 in core/updates testings also fixes expiring /usr/share/distribution-gpg-keys/mageia/RPM-GPG-KEY-Mageia.

$ gpg2 --show-key /usr/share/distribution-gpg-keys/mageia/RPM-GPG-KEY-Mageia
pub   rsa4096 2011-02-07 [SCEA] [expires: 2029-12-31]
      00EDB89585B012A8916F0DF8B742FA8B80420F66
uid                      Mageia Packages <packages@mageia.org>


SRPMS:
distribution-gpg-keys-1.89-1.1.mga9
mageia-repos-9-4.1.mga9

RPMS:
distribution-gpg-keys-1.89-1.1.mga9
mageia-repos-9-4.1.mga9
mageia-repos-cauldron-9-4.1.mga9
mageia-repos-keys-9-4.1.mga9
mageia-repos-pkgprefs-9-4.1.mga9
Jani Välimaa 2025-12-30 18:54:17 CET

Source RPM: mageia-repos-9-4.mga9 => mageia-repos-9-4.mga9, distribution-gpg-keys-1.89-1.mga9

Comment 15 katnatek 2025-12-30 19:28:38 CET
I not find issues building with mock before & after update
If that is enough test please restore OK and validation
Comment 16 katnatek 2025-12-30 19:30:22 CET
Advisory updated
Comment 17 Jani Välimaa 2025-12-30 21:04:08 CET
Better to get this one FIXED.

Keywords: (none) => validated_update

Comment 18 Mageia Robot 2025-12-31 00:01:43 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGAA-2025-0108.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED

katnatek 2025-12-31 02:09:34 CET

Keywords: (none) => IN_ERRATA9

katnatek 2025-12-31 02:20:04 CET

Keywords: (none) => IN_RELEASENOTES10


Note You need to log in before you can comment on or make changes to this bug.