๐ŸŒŒ OS/Linux-๋ฆฌ๋ˆ…์Šค

[E] CentOS 7์—์„œ rpm ํŒจํ‚ค์ง€ ์„ค์น˜์‹œ Header V4 RSA/SHA1 Signature, key ID f27eab47: BAD ์—๋Ÿฌ ๋ฐœ์ƒ

mxnxeonx 2023. 4. 11. 15:47
728x90
728x90

CentOS 7 ํ™˜๊ฒฝ์—์„œ GitLab์„ ์„ค์น˜ํ•˜๋Š” ์ค‘ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์—๋Ÿฌ๊ฐ€ ๋ฐœ์ƒํ–ˆ๋‹ค. ๋งˆ์ง€๋ง‰์— Complete ๋ฉ”์‹œ์ง€๋งŒ ๋ณด๊ณ  ์„ค์น˜๊ฐ€ ๋๋‚˜? ํ–ˆ๋Š”๋ฐ ์„ค์น˜์— ์‹คํŒจํ•ด์„œ ์„ค์น˜ ํ”„๋กœ์„ธ์Šค๊ฐ€ ๊ทธ๋ƒฅ ๋๋‚ฌ๋‹ค๋Š” ๋œป์ธ๋“ฏ. ์—๋Ÿฌ๋ฅผ ํ•ด๊ฒฐํ•ด์•ผ ์„ค์น˜ํ•  ์ˆ˜ ์žˆ๊ธฐ์— ... ๋˜ ์‚ฝ์งˆํ•œ๋‹ค.

$ sudo yum install gitlab-ce-15.10.2-ce.0.el7.x86_64.rpm
์˜ค๋ฅ˜: gitlab-ce-15.10.2-ce.0.el7.x86_64: Header V4 RSA/SHA1 Signature, key ID f27eab47: BAD
gitlab-ce-15.10.2-ce.0.el7.x86_64 was supposed to be installed but is not!
  Verifying  : gitlab-ce-15.10.2-ce.0.el7.x86_64                                                                                                                                                                                  1/1 
  Verifying  : gitlab-ce-15.10.2-ce.0.el7.x86_64                                                                                                                                                                                  2/1 

Failed:
  gitlab-ce.x86_64 0:15.10.2-ce.0.el7                                                                                                                                                                                                 

Complete!

 

๋ฐœ์ƒ ์›์ธ

RedHat OS์—์„œ rpm ํŒจํ‚ค์ง€ ์„ค์น˜์‹œ ๋ฐœ์ƒํ•˜๋Š” ์˜ค๋ฅ˜์ธ๋ฐ, CentOS ๋ฒ„์ „๋งˆ๋‹ค GPG Signature ๋ฒ„์ „์ด ๋‹ฌ๋ผ์„œ ๋ฐœ์ƒํ•œ๋‹ค.

โ€ป CentOS๋Š” ์œ ๋ฃŒ Linux ๋ฐฐํฌํŒ์ธ RedHat(๋ ˆ๋“œํ–‡)์—์„œ ํŒŒ์ƒ๋œ OS๋กœ ๋ ˆ๋“œํ–‡์˜ ๊ธฐ์ˆ ์„ ๊ฑฐ์˜ ๊ทธ๋Œ€๋กœ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š”? ๋ ˆ๋“œํ–‡์˜ ๋ฌด๋ฃŒ ๋ฒ„์ „ OS 

 

CentOS ํ™ˆํŽ˜์ด์ง€์—์„œ ์ œ๊ณตํ•˜๋Š” ์ •๋ณด์— ๋”ฐ๋ฅด๋ฉด, CentOS๋Š” GPG Keys๋ฅผ ์‚ฌ์šฉํ•˜๊ณ  yum ๋“ฑ ํŒจํ‚ค์ง€ ์„ค์น˜ ๋„๊ตฌ๋ฅผ ์‚ฌ์šฉํ–ˆ์„ ๋•Œ ํŒจํ‚ค์ง€์—์„œ ์„œ๋ช…๋œ GPG Keys ๋ฒ„์ „๊ณผ CentOS์—์„œ ์ง€์›ํ•˜๋Š” GPG Keys์˜ ๋ฒ„์ „์ด ๋‹ค๋ฅด๋ฉด ํŒจํ‚ค์ง€ ์„ค์น˜๊ฐ€ ๊ฑฐ๋ถ€๋œ๋‹ค๊ณ  ํ•œ๋‹ค. ๋ฒˆ๊ฑฐ๋กญ๊ฒŒ GPG Keys๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ์ด์œ ๋Š” ์„œ๋ฒ„์— Installํ•  ํŒจํ‚ค์ง€๊ฐ€ CentOS๊ฐ€ ๋ณด์ฆํ•  ์ˆ˜ ์žˆ๋‹ค๋Š” ๋œป์ด๋ผ๊ณ .

โ€ป ์˜์•Œ๋ชป์ด๋ผ ํ•ด์„์ด ์ •ํ™•ํ•˜์ง€ ์•Š์„ ์ˆ˜ ์žˆ์Œ

 

์œ„ ๋‚ด์šฉ์„ ํ† ๋Œ€๋กœ ๋” ์ฐพ์•„๋ณด๊ณ  ๊ณต๋ถ€ํ•œ ๋‚ด์šฉ์„ ์š”์•ฝํ•ด์„œ ์จ๋ณด๋ฉด ์ด๋ ‡๋‹ค.

  1. RedHat ๊ณ„์—ด Linux๋Š” rpm ๊ธฐ๋ฐ˜์˜ ํŒจํ‚ค์ง€ ๊ด€๋ฆฌ ์ฒด๊ณ„๋ฅผ ๊ฐ€์ ธ yum์œผ๋กœ ํŒจํ‚ค์ง€ ์„ค์น˜์‹œ rpm ํŒจํ‚ค์ง€ DB๋ฅผ ํ† ๋Œ€๋กœ ๋™์ž‘
  2. ์ด๋Ÿฌํ•œ rpm ๊ธฐ๋ฐ˜ ํŒจํ‚ค์ง€๋“ค์€ RPM GPG Key๋ผ๋Š” ๊ณต๊ฐœํ‚ค ์ „์ž ์„œ๋ช…๊ณผ ๊ฒ€์ฆ์„ ํ†ตํ•ด ํ•ด๋‹น ํŒจํ‚ค์ง€๋ฅผ ๋ณด์ฆ
  3. ๋•Œ๋ฌธ์— Public GPG Keys๊ฐ€ ๋ฏธ๋“ฑ๋ก ํ˜น์€ ๋งŒ๋ฃŒ ์ƒํƒœ์ธ ๊ฒฝ์šฐ yum์œผ๋กœ rpm ํŒจํ‚ค์ง€๋ฅผ ์„ค์น˜ํ•  ์ˆ˜ ์—†์Œ.
๊ทธ๋Ÿฌ๋‹ˆ๊นŒ, RPM-GPG-KEY(๊ณต๊ฐœํ‚ค ๊ธฐ๋ฐ˜์˜ ๋””์ง€ํ„ธ ์„œ๋ช…)๋ผ๋Š” ๊ฒƒ์„ ๋“ฑ๋กํ•ด์•ผ rpm ํŒจํ‚ค์ง€๋ฅผ ์„ค์น˜ํ•  ์ˆ˜ ์žˆ๋‹ค๋Š” ๋œป์ด ๋จ!
  • CentOS 5 : V3
  • CentOS 6 : V4
  • CentOS 7 : 

 


 

ํ•ด๊ฒฐ ๋ฐฉ๋ฒ•

1) RPM GPG KEY ์„ค์น˜ ์œ ๋ฌด ํ™•์ธ

RPM GPG KEY๊ฐ€ ์„ค์น˜๋˜์–ด ์žˆ๋Š”์ง€ ํ™•์ธํ•œ๋‹ค. gpg-pubkey๋กœ ์‹œ์ž‘ํ•˜๋Š” ๋ฉ”์‹œ์ง€๊ฐ€ ์—†๋‹ค๋ฉด ์„ค์น˜๋˜์ง€ ์•Š์€ ๊ฒƒ์ด๋‹ค. ๋‘ ๋ฒˆ์งธ ๋ช…๋ น์–ด๋Š” ํ˜„์žฌ OS์˜ ๋ฒ„์ „์„ ํ™•์ธํ•˜๋Š” ๊ฑด๋ฐ, OS ๋ฒ„์ „์„ ํ™•์ธํ•ด์•ผ 2๋ฒˆ์—์„œ RPM GPG KEY๋ฅผ ์„ค์น˜ํ•  ์ˆ˜ ์žˆ๋‹ค.

$ rpm -qa | grep gpg
libgpg-error-1.12-3.el7.x86_64

$ rpm -qa *-release
centos-release-7-9.2009.1.el7.centos.x86_64

 

2) RPM GPG KEY ์„ค์น˜

๊ณผ์ • 1์—์„œ ํ™•์ธํ•œ OS ๋ฒ„์ „์œผ๋กœ RPM GPG KEY๋ฅผ ์„ค์น˜ํ•œ๋‹ค. (rpm --import RPM-GPG-KEY-CentOS-{CentOS๋ฒ„์ „}) ์„ค์น˜๊ฐ€ ๋˜๋ฉด ๋‹ค์‹œ RPM GPG KEY ๋ฆฌ์ŠคํŠธ๋ฅผ ํ™•์ธํ•˜๊ณ , ์ถ”๊ฐ€๋œ gpg-pubkey~๋ฅผ ์ „์ฒด ๋ณต์‚ฌํ•˜์—ฌ rpm -qi ๋ช…๋ น ๋’ค์— ๋ถ™์—ฌ๋„ฃ๋Š”๋‹ค. ์„ค์น˜๊ฐ€ ์ž˜ ๋˜์—ˆ๋‹ค๋ฉด ํ•ด๋‹น ์ •๋ณด๊ฐ€ ์•„๋ž˜ ํ‘œ์‹œ๋  ๊ฒƒ์ด๋‹ค.

$ rpm --import RPM-GPG-KEY-CentOS-7       # RPM GPG KEY ์„ค์น˜

$ rpm -qa | grep gpg                      # RPM GPG KEY ํ™•์ธ (gpg-pubkey-f4a80eb5-53a7ff4b ์ถ”๊ฐ€๋จ)
libgpg-error-1.12-3.el7.x86_64
gpg-pubkey-f4a80eb5-53a7ff4b

$ rpm -qi gpg-pubkey-f4a80eb5-53a7ff4b    # RPM GPG KEY ์„ค์น˜ ํ™•์ธ
Name        : gpg-pubkey
Version     : f4a80eb5
Release     : 53a7ff4b
Architecture: (none)
Install Date: 2023๋…„ 04์›” 07์ผ (๊ธˆ) ์˜ค์ „ 02์‹œ 43๋ถ„ 21์ดˆ
Group       : Public Keys
Size        : 0
License     : pubkey
Signature   : (none)
Source RPM  : (none)
Build Date  : 2014๋…„ 06์›” 23์ผ (์›”) ์˜คํ›„ 07์‹œ 19๋ถ„ 55์ดˆ
Build Host  : localhost
Relocations : (not relocatable)
Packager    : CentOS-7 Key (CentOS 7 Official Signing Key) <security@centos.org>
Summary     : gpg(CentOS-7 Key (CentOS 7 Official Signing Key) <security@centos.org>)
Description :
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: rpm-4.11.3 (NSS-3)

 

๋”๋ณด๊ธฐ

๋‚˜์˜ ๊ฒฝ์šฐ RPM GPG KEY๊ฐ€ ์„ค์น˜๋˜์–ด ์žˆ์—ˆ๊ณ , ๋ฒ„์ „๋„ Requires์— ๋ช…์‹œ๋œ ๊ฒƒ๊ณผ ์ผ์น˜ํ–ˆ์œผ๋‚˜ ์ด์ƒํ•˜๊ฒŒ rpm ํŒจํ‚ค์ง€ ์„ค์น˜๊ฐ€ ๋˜์ง€ ์•Š์•˜๋‹ค. ์•„๋ž˜ ๋ช…๋ น์–ด ์ž…๋ ฅ ๊ธฐ๋ก์„ ๋ณด๋ฉด gpg-pubkey๊ฐ€ ์ด๋ฏธ ๋“ฑ๋ก๋˜์–ด ์žˆ๊ณ , ์ƒˆ๋กœ ์„ค์น˜ํ•˜๋ ค๊ณ  ํ•˜๋‹ˆ failed๊ฐ€ ๋œธ.

$ rpm -qa | grep gpg
libgpg-error-1.12-3.el7.x86_64
gpg-pubkey-f4a80eb5-53a7ff4b
pygpgme-0.3-9.el7.x86_64
gpgme-1.3.2-5.el7.x86_64

$ rpm -qa *-release
centos-release-7-9.2009.1.el7.centos.x86_64

$ rpm --import RPM-GPG-KEY-CentOS-7
์˜ค๋ฅ˜: RPM-GPG-KEY-CentOS-7: import read failed(2).

$ rpm -qi gpg-pubkey-f4a80eb5-53a7ff4b
Name        : gpg-pubkey
Version     : f4a80eb5
Release     : 53a7ff4b
Architecture: (none)
Install Date: 2023๋…„ 04์›” 07์ผ (๊ธˆ) ์˜ค์ „ 02์‹œ 43๋ถ„ 21์ดˆ
Group       : Public Keys
Size        : 0
License     : pubkey
Signature   : (none)
Source RPM  : (none)
Build Date  : 2014๋…„ 06์›” 23์ผ (์›”) ์˜คํ›„ 07์‹œ 19๋ถ„ 55์ดˆ
Build Host  : localhost
Relocations : (not relocatable)
Packager    : CentOS-7 Key (CentOS 7 Official Signing Key) <security@centos.org>
Summary     : gpg(CentOS-7 Key (CentOS 7 Official Signing Key) <security@centos.org>)
Description :
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: rpm-4.11.3 (NSS-3)

 

๊ทธ๋ž˜์„œ ์ด๊ฒƒ์ €๊ฒƒ ์‹œ๋„ํ•ด๋ณด๋‹ค๊ฐ€ gpg config ํŒŒ์ผ์„ ์ƒ์„ฑํ•ด๋ณด๋‹ˆ ํ•ด๊ฒฐ๋˜์—ˆ๋‹ค. ์ด ํŒŒ์ผ์ด ์–ด๋–ค ์—ญํ• ์ธ์ง€๋„, ์™œ ํ•ด๊ฒฐ๋œ์ง€๋„ ๋ชจ๋ฅด๊ฒ ์œผ๋‚˜ ์œ„ ๋ฐฉ๋ฒ•๊นŒ์ง€ ๋ชจ๋‘ ์‹œ๋„ํ•ด๋ณด์•˜๋Š”๋ฐ ์•ˆ๋˜๋Š” ๊ฒฝ์šฐ ์•„๋ž˜ ๋ช…๋ น ์ž…๋ ฅํ•ด๋ณด๋ฉด ํ•ด๊ฒฐ๋ ์ˆ˜๋„.

$ gpg --quiet --with-fingerprint /etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-7
gpg: new configuration file `/home/idox/.gnupg/gpg.conf' created
gpg: WARNING: options in `/home/idox/.gnupg/gpg.conf' are not yet active during this run
pub  4096R/F4A80EB5 2014-06-23 CentOS-7 Key (CentOS 7 Official Signing Key) <security@centos.org>
      Key fingerprint = 6341 AB27 53D7 8A78 A7C2  7BB1 24C6 A8A7 F4A8 0EB5
728x90
320x100