Uploaded image for project: 'ZABBIX BUGS AND ISSUES'
  1. ZABBIX BUGS AND ISSUES
  2. ZBX-22107

RHEL 9 packages signed with SHA1 fails to install

XMLWordPrintable

    • Icon: Problem report Problem report
    • Resolution: Fixed
    • Icon: Trivial Trivial
    • None
    • None
    • Agent (G)
    • None
    • RHEL 9
    • Team B
    • Sprint 95 (Dec 2022), Sprint 96 (Jan 2023)

      SHA1 algorithm has been deprecated in RHEL 9 [1]. Zabbix agent2 package fails to install on RHEL 9 system. Maybe Zabbix should sign the package with some other, modern algorithm?

      Steps to reproduce:

      1. Install zabbix-agent2-6.2.4-release1.el9.x86_64 on RHEL 9 system

      Result:
      Zabbix 6.2 RHEL 9 x86_64                                                 
      Importing GPG key 0xA14FE591:
       Userid     : "Zabbix LLC <[email protected]>"
       Fingerprint: A184 8F53 52D0 22B9 471D 83D0 082A B56B A14F E591
       From       : <URL removed>
      warning: Signature not supported. Hash algorithm SHA1 not available.
      Key import failed (code 2). Failing package is: zabbix-agent2-6.2.4-release1.el9.x86_64
       GPG Keys are configured as: <URL removed>
      The downloaded packages were saved in cache until the next successful transaction.
      You can remove cached packages by executing 'dnf clean packages'.
      Error: GPG check FAILED

      [1]Enhancing RHEL Security: Understanding SHA-1 deprecation on RHEL 9

            jlambda Juris Lambda
            Bergman svb
            Team B
            Votes:
            2 Vote for this issue
            Watchers:
            6 Start watching this issue

              Created:
              Updated:
              Resolved: