fyi,
after `dnf system-upgrade` of F38 -> F39,
on
lsb_release -rd
Description: Fedora release 39 (Thirty Nine)
Release: 39
with
dnf --version
4.18.1
Installed: dnf-0:4.18.1-1.fc39.noarch at Sat 11 Nov 2023 01:38:21 PM GMT
Built : Fedora Project at Tue 07 Nov 2023 08:56:26 AM GMT
Installed: rpm-0:4.19.0-1.fc39.x86_64 at Sat 11 Nov 2023 01:38:06 PM GMT
Built : Fedora Project at Tue 19 Sep 2023 01:02:12 PM GMT
exec of any `dnf *` cmd, reports Fedora's GPG key as 'revoked',
dnf update
DNSSEC extension: Testing already imported keys for their validity.
!! DNSSEC extension: GPG Key fedora-39-primary@xxxxxxxxxxxxxxxxx has been revoked and should be removed immediately
Dependencies resolved.
Nothing to do.
Complete!
checking,
rpm -q gpg-pubkey --qf '%{NAME}-%{VERSION}-%{RELEASE}\t%{SUMMARY}\n' | grep fedora-
gpg-pubkey-12c944d0-5d5156ab Fedora (32) <fedora-32-primary@xxxxxxxxxxxxxxxxx> public key
gpg-pubkey-9570ff31-5e3006fb Fedora (33) <fedora-33-primary@xxxxxxxxxxxxxxxxx> public key
gpg-pubkey-45719a39-5f2c0192 Fedora (34) <fedora-34-primary@xxxxxxxxxxxxxxxxx> public key
gpg-pubkey-9867c58f-601c49ca Fedora (35) <fedora-35-primary@xxxxxxxxxxxxxxxxx> public key
gpg-pubkey-38ab71f4-60242b08 Fedora (36) <fedora-36-primary@xxxxxxxxxxxxxxxxx> public key
gpg-pubkey-5323552a-6112bcdc Fedora (37) <fedora-37-primary@xxxxxxxxxxxxxxxxx> public key
gpg-pubkey-eb10b464-6202d9c6 Fedora (38) <fedora-38-primary@xxxxxxxxxxxxxxxxx> public key
gpg-pubkey-18b8e74c-62f2920f Fedora (39) <fedora-39-primary@xxxxxxxxxxxxxxxxx> public key
where
ls -al /etc/pki/rpm-gpg/*fedora-39*
lrwxrwxrwx 1 root root 29 Oct 5 20:00 /etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-39-aarch64 -> RPM-GPG-KEY-fedora-39-primary
lrwxrwxrwx 1 root root 29 Oct 5 20:00 /etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-39-ppc64le -> RPM-GPG-KEY-fedora-39-primary
-rw-r--r-- 1 root root 1.7K Oct 5 20:00 /etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-39-primary
lrwxrwxrwx 1 root root 29 Oct 5 20:00 /etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-39-s390x -> RPM-GPG-KEY-fedora-39-primary
lrwxrwxrwx 1 root root 29 Oct 5 20:00 /etc/pki/rpm-gpg/RPM-GPG-KEY-fedora-39-x86_64 -> RPM-GPG-KEY-fedora-39-primary
rpm -q --whatprovides /etc/pki/rpm-gpg/*fedora-39*
fedora-gpg-keys-39-1.noarch
fedora-gpg-keys-39-1.noarch
fedora-gpg-keys-39-1.noarch
fedora-gpg-keys-39-1.noarch
fedora-gpg-keys-39-1.noarch
dnf info fedora-gpg-keys-39-1.noarch
DNSSEC extension: Testing already imported keys for their validity.
DNSSEC extension: GPG Key fedora-39-primary@xxxxxxxxxxxxxxxxx has been revoked and should be removed immediately
Installed Packages
Name : fedora-gpg-keys
Version : 39
Release : 1
Architecture : noarch
Size : 123 k
Source : fedora-repos-39-1.src.rpm
Repository : @System
From repo : fedora
Summary : Fedora RPM keys
URL : https://fedoraproject.org/
License : MIT
Description : This package provides the RPM signature keys.
which looks to be the current/latest
https://packages.fedoraproject.org/pkgs/fedora-repos/fedora-gpg-keys/fedora-39.html
Date Author Change
2023-10-06 Kevin Fenzi <kevin at scrye dot com> - 39-1 - Disable updates_testing for release.
fwiw, those keys have only been installed by the system upgrade process; at least, never installed manually by me
_______________________________________________
devel mailing list -- devel@xxxxxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to devel-leave@xxxxxxxxxxxxxxxxxxxxxxx
Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/devel@xxxxxxxxxxxxxxxxxxxxxxx
Do not reply to spam, report it: https://pagure.io/fedora-infrastructure/new_issue