Bug 1160455

Summary: Signature verification failed for file 'repomd.xml' from repository 'NVIDIA'.
Product: [openSUSE] openSUSE Distribution Reporter: James Rome <jamesrome>
Component: MaintenanceAssignee: Stefan Dirsch <sndirsch>
Status: RESOLVED FIXED QA Contact: E-mail List <qa-bugs>
Severity: Major    
Priority: P2 - High CC: ddadap
Version: Leap 15.1   
Target Milestone: ---   
Hardware: IA64   
OS: Other   
Whiteboard:
Found By: --- Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description James Rome 2020-01-08 14:40:50 UTC
Retrieving repository 'NVIDIA' metadata ---------------------------------------------------------------------------------------[\]
Signature verification failed for file 'repomd.xml' from repository 'NVIDIA'.

    Note: Signing data enables the recipient to verify that no modifications occurred after the data
    were signed. Accepting data with no, wrong or unknown signature can lead to a corrupted system
    and in extreme cases even to a system compromise.

    Note: File 'repomd.xml' is the repositories master index file. It ensures the integrity of the
    whole repo.

    Warning: This file was modified after it has been signed. This may have been a malicious change,
    so it might not be trustworthy anymore! You should not continue unless you know it's safe.

Signature verification failed for file 'repomd.xml' from repository 'NVIDIA'. Continue? [yes/no] (no): yes

Warning: Digest verification failed for file 'susedata.xml.gz'
[/var/adm/mount/AP_0xmaz4AJ/repodata/susedata.xml.gz]

  expected cdbdd32e451704423e592e66938d867fa38b7e26bae9356bdf2d5e3df41886cd
  but got  4acc8d0d91343a37521678452c846572217179feb8fba9fba4a630f85eb85992
Comment 1 Stefan Dirsch 2020-01-08 16:52:42 UTC
Indeed repos are currently broken, i.e. checksums are wrong. :-( Daniel, could you have a look?
Comment 2 Stefan Dirsch 2020-01-08 17:07:59 UTC
NVIDIA is currently looking into this issue. Should be fixed shortly.
Comment 3 Stefan Dirsch 2020-01-09 20:50:36 UTC
Repositories meanwhile are working again. Thanks, Daniel for adressing this immediately!