Saturday, April 30, 2016

Re: Download verification broken

2016-04-28 3:10 GMT+02:00 Dan Haskell <dan_haskell@mentor.com>:
Downloaded iso of the server edition. Tried to verify following instructions and failed. First your key is not certified.

> gpg --verify-files Fedora-Server-23-x86_64-CHECKSUM
gpg: Signature made Fri 30 Oct 2015 01:31:05 PM PDT using RSA key ID 34EC9CBA
gpg: Good signature from "Fedora (23) <fedora-23-primary@fedoraproject.org>" [unknown]
gpg: WARNING: This key is not certified with a trusted signature!
gpg:          There is no indication that the signature belongs to the owner.
Primary key fingerprint: EF45 5106 80FB 0232 6B04  5AFB 3247 4CF8 34EC 9CBA

Second, it appears to be the wrong key(?)

> ls
Fedora-Server-23-x86_64-CHECKSUM  Fedora-Server-DVD-x86_64-23.iso

> sha256sum -c Fedora-Server-23-x86_64-CHECKSUM
Fedora-Server-DVD-x86_64-23.iso: OK
sha256sum: Fedora-Server-netinst-x86_64-23.iso: No such file or directory
Fedora-Server-netinst-x86_64-23.iso: FAILED open or read
sha256sum: WARNING: 20 lines are improperly formatted
sha256sum: WARNING: 1 listed file could not be read


Couldn't you just provide a md5sum instead? The gpg stuff is cool and all, but when it fails... give us something to work with. Clicked on support, but it's just a link to a BUNCH of forums. Not helpful.

Dan


--
websites mailing list
websites@lists.fedoraproject.org
http://lists.fedoraproject.org/admin/lists/websites@lists.fedoraproject.org


You have a good signature, so the ISO id ok. The rest only says the key doesn't have a certified signature, AFAIK we will try to include some text message in the future to give users a better resume, but won't provide md5sum.
Regards.

--
Robert Mayr
(robyduck)

No comments:

Post a Comment