[NTLUG:Discuss] Weird Fedora Updates

Justin M. Forbes 64bit_fedora at comcast.net
Mon Jan 12 11:34:43 CST 2004


On Mon, Jan 12, 2004 at 10:56:41AM -0600, David Simmons wrote:
> Guys,
> 
> Was just talking about this last night! -geez
> 
> Came in this morning and booted my Fedora workstation.  There were 30+
> updates on a variety of packages and the kernel.  When trying to
> up2date, it complained about Galeon...removed Mozilla from the group and
> 'let er rip'....then it complained that the Kernel-source didn't have a
> valid GPG key, and it was tampered with.
> 
> Ahhh...have the Fedora updates been 0wned?  Is anyone else
> seeing/getting this?

There were several updates, mainly because of httpd and php (one SRPM for
each, many built packages).  There has not been a breech on Fedora Updates,
but dave rushed the errata kernel out to address a security issue and it
may have a gpg key from the build system for test still instead of
production.  You might try 'rpm --import /mnt/cdrom/RPM-GPG-KEY-*' with FC1
CD1 mounted, that should bring in all valid Red Hat GPG keys.

Justin



More information about the Discuss mailing list