[ZBX-26171] Wrong GPG signature for unstable RPM package release Created: 2025 Mar 14  Updated: 2025 Mar 14

Status: Open
Project: ZABBIX BUGS AND ISSUES
Component/s: Packages (C)
Affects Version/s: 7.0.11rc1
Fix Version/s: None

Type: Incident report Priority: Trivial
Reporter: Marks Sunins Assignee: Marks Sunins
Resolution: Unresolved Votes: 0
Labels: packaging, release
Remaining Estimate: Not Specified
Time Spent: Not Specified
Original Estimate: Not Specified
Environment:

enterprise linux


Attachments: PNG File image-2025-03-14-13-01-36-421.png    
Team: Team I
Story Points: 2

 Description   

Steps to reproduce:

  1. Follow official package installation instruction for any component. Perform clean install.
    1. Package type: RPM
    2. Affected systems: Enterprise Linux
    3. Package version: 7.0.11rc1{}
    4. Stream: Unstable
    5. Does not affect updating users, only clean installation.
  2. Configure /etc/yum.repos.d/zabbix.repo to point only unstable release (7.0.11rc1):
    [zabbix]
    name=Zabbix Official Repository - $basearch
    baseurl=https://repo.zabbix.com/zabbix/7.0/alma/9/$basearch/
    enabled=0
    gpgcheck=1
    gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-ZABBIX-B5333005
    
    [zabbix-non-supported]
    name=Zabbix Official Repository (non-supported) - $basearch
    baseurl=https://repo.zabbix.com/non-supported/rhel/9/$basearch/
    enabled=0
    gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-ZABBIX-08EFA7DD
    gpgcheck=1
    
    [zabbix-unstable]
    name=Zabbix Official Repository (unstable) - $basearch
    baseurl=hhttps://repo.zabbix.com/zabbix/7.0/unstable/alma/9/$basearch/enabled=1
    gpgcheck=1
    gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-ZABBIX-08EFA7DD
    
    [zabbix-sources]
    name=Zabbix Official Repository (source code) - $basearch
    baseurl=https://repo.zabbix.com/zabbix/7.0/alma/9/SRPMS
    enabled=0
    gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-ZABBIX-B5333005
    gpgcheck=1 
  1. Attempt to install components.

 

Result:

User gets notification:

The GPG keys listed for the "Zabbix Official Repository (unstable)" repository are already installed but they are not correct for this package. Check that the correct key URLs are configured for this repository. 

Expected:

Components are installed. Unstable stream signed using correct GPG keys.


Generated at Fri Apr 04 22:24:48 EEST 2025 using Jira 9.12.4#9120004-sha1:625303b708afdb767e17cb2838290c41888e9ff0.