Top Menu

Jump to content
Home
    Modules
      • Projects
      • Activity
      • Work packages
      • Gantt charts
      • Calendars
      • Team planners
      • Boards
      • News
    • Getting started
    • Introduction video
      Welcome to OpenProject Community
      Get a quick overview of project management and team collaboration with OpenProject. You can restart this video from the help menu.

    • Help and support
    • Upgrade to Enterprise edition
    • User guides
    • Videos
    • Shortcuts
    • Community forum
    • Enterprise support

    • Additional resources
    • Data privacy and security policy
    • Digital accessibility (DE)
    • OpenProject website
    • Security alerts / Newsletter
    • OpenProject blog
    • Release notes
    • Report a bug
    • Development roadmap
    • Add and edit translations
    • API documentation
  • Sign in
      Forgot your password?

      or sign in with your existing account

      Google

Side Menu

  • Overview
  • Activity
    Activity
  • Roadmap
  • Work packages
    Work packages
  • Gantt charts
    Gantt charts
  • Calendars
    Calendars
  • Team planners
    Team planners
  • Boards
    Boards
  • News
  • Forums

Content

Support Installation & Updates
  1. OpenProject
  2. Forums
  3. Support Installation & Updates
  4. 7.2.0: Centos7 package not signed

7.2.0: Centos7 package not signed

Added by Richard Asplin over 7 years ago

Getting this message on the upgrade to 7.2.0:

Package openproject-7.2.0-1502277838.ef02b087.centos7.x86_64.rpm is not signed

Is this a fault with the packager, or is there something wrong with my install environment?


Replies (6)

RE: 7.2.0: Centos7 package not signed - Added by Cyril Rohr over 7 years ago

Hello,

I couldn’t reproduce the issue. Packager.io was undergoing a 10 min maintenance window 40 minutes ago, so maybe you tried in the middle of it?

Is there any way for you to send more debug output if you retry and it fails again?

RE: 7.2.0: Centos7 package not signed - Added by Richard Asplin over 7 years ago

I deleted the package from the cache and tried again - same deal…

[richarda@currywurst packages]$ rpm -K openproject-7.2.0-1502277838.ef02b087.centos7.x86_64.rpm
openproject-7.2.0-1502277838.ef02b087.centos7.x86_64.rpm: sha1 md5 OK

note the lack of ‘gpg’ in the message - this is what I get if it run rpm -K against an old 6.1.4 package which is in the cache:

openproject-6.1.4-1486730985.5bf684b.centos7.x86_64.rpm: rsa sha1 (md5) pgp md5 OK

RE: 7.2.0: Centos7 package not signed - Added by Cyril Rohr over 7 years ago

Packages have never been signed. Only the repository metadata are signed, and contain shashum to verify the package integrity.

Can you tell what’s the output of running the install instructions at:
https://packager.io/gh/opf/openproject-ce/builds/442/install/centos-7

Also, your apt source file at /etc/yum.repos.d/openproject-ce.repo should have the following:

gpgcheck=0
repo_gpgcheck=1

RE: 7.2.0: Centos7 package not signed - Added by Richard Asplin over 7 years ago

Thank you :-) Amending the .repo to add the parameters in the latest version made this work. FYI, I haven’t changed the repo file since my first install (OpenProject 6.0, if not earlier), and the contents of the repo were a lot different than the new version, with me only tweaking ‘6’ to ‘7’:

[openproject]
name=Repository for opf/openproject-ce application.
baseurl=https://rpm.packager.io/gh/opf/openproject-ce/centos7/stable/7
enabled=1

Despite lacking the parameters in the latest download, I’ve been able to upgrade through and up to 7.1.0, so I suspect other users may come across this soon…

RE: 7.2.0: Centos7 package not signed - Added by Richard Asplin over 7 years ago

Richard Asplin wrote:

Despite lacking the parameters in the latest download, I’ve been able to upgrade through and up to 7.1.0, so I suspect other users may come across this soon…

Indeed - anyone following the install instructions on your website will probably have the install fail as of 7.2.0: https://www.openproject.org/download-and-installation/

Best get it updated :-)

RE: 7.2.0: Centos7 package not signed - Added by Cyril Rohr over 7 years ago

OK, I’ve sent a PR to update the install URLs to use the new repo file, which explicitly states that RPM files themselves are not signed.

https://github.com/opf/openproject/pull/5841

Thanks,
Cyril

  • (1 - 6/6)
Loading...