You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hi,
I've been using Uyuni and its ancestors such as SuSE Manager for several years, however I am still a bit uncertain what is the correct procedure to add a third-party repo so that it could be assigned to a client without the need to manually import the GPG key.
First, I thought it is enough to add GPG key URL, GPG key ID, GPG key Fingerprint and Enable GPG Check while creating a new channel, but I've noticed that clients complaint about missing GPG key on a first install unless the channel was manually added before.
There is GPG documentation explaining about using Salt to push GPG keys, but is this the recommended way?
Then there is documentation about 3rd party repos which suggest using mgradm gpg add command to add GPG keys.
I guess Uyuni can also sign third party repos itself using its own key, but if there is an easier way to deliver 3rd party GPG keys to the clients that is probably a better solution.
And finally I get confused about the "Has Signed Metadata?" checkbox in Repository details, is it supposed to be checked on a 3rd party RHEL type repository such as PostgreSQL or Zabbix?
Sorry if these are explained somewhere, I just haven't found a clear best practice what to do with all those GPG options and what is their difference.
reacted with thumbs up emoji reacted with thumbs down emoji reacted with laugh emoji reacted with hooray emoji reacted with confused emoji reacted with heart emoji reacted with rocket emoji reacted with eyes emoji
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Hi,
I've been using Uyuni and its ancestors such as SuSE Manager for several years, however I am still a bit uncertain what is the correct procedure to add a third-party repo so that it could be assigned to a client without the need to manually import the GPG key.
First, I thought it is enough to add GPG key URL, GPG key ID, GPG key Fingerprint and Enable GPG Check while creating a new channel, but I've noticed that clients complaint about missing GPG key on a first install unless the channel was manually added before.
There is GPG documentation explaining about using Salt to push GPG keys, but is this the recommended way?
Then there is documentation about 3rd party repos which suggest using
mgradm gpg addcommand to add GPG keys.I guess Uyuni can also sign third party repos itself using its own key, but if there is an easier way to deliver 3rd party GPG keys to the clients that is probably a better solution.
And finally I get confused about the "Has Signed Metadata?" checkbox in Repository details, is it supposed to be checked on a 3rd party RHEL type repository such as PostgreSQL or Zabbix?
Sorry if these are explained somewhere, I just haven't found a clear best practice what to do with all those GPG options and what is their difference.
All reactions