Google repositories use RSA/SHA1 for signing packages. However the SHA1 has been disabled by default on el9/c9s. Since osbuild-composer imports GPG keys specified in the repository definition unconditionally, this creates issues when installing rpms signed with the key by osbuild [1]. Remove GPG keys in all el9/c9s GCP repo definitions and disable GPG signature verification until [2] is resolved. [1] https://github.com/osbuild/osbuild/issues/991 [2] https://issuetracker.google.com/issues/223626963 Signed-off-by: Tomas Hozza <thozza@redhat.com> |
||
|---|---|---|
| .. | ||
| ansible | ||
| azure | ||
| cloud-init | ||
| composer | ||
| kerberos | ||
| keyring | ||
| koji | ||
| manifests | ||
| openshift | ||
| repositories | ||
| upgrade8to9 | ||
| worker | ||
| x509 | ||