Hi, I wrote on this and got an answer. Updating rpm seemed to correct the issue partially. I'm running rpm 4.4.2.3-18.el5.x86_64 on centos 5.3. The update went fine. I can now sign packages and most of the signatures verify. Header V3 RSA/SHA1 Signature: bad Key id <Key ID> Header SHA1 Digest OK MD5 Digest: OK Could it be the package rpm uses to verify the signatures, openssl for example? Thanks. Dave. _______________________________________________ Rpm-list mailing list Rpm-list@xxxxxxxxxxxxx http://lists.rpm.org/mailman/listinfo/rpm-list