GNU bug report logs - #35414
26.2; ELPA packages signed with second, unknown key

Previous Next

Package: emacs;

Reported by: Brandon Invergo <brandon <at> invergo.net>

Date: Wed, 24 Apr 2019 12:57:01 UTC

Severity: important

Tags: security

Merged with 35534, 44907

Found in versions 25.3.50, 26.2

Done: Stefan Monnier <monnier <at> iro.umontreal.ca>

Bug is archived. No further changes may be made.

Full log


View this message in rfc822 format

From: help-debbugs <at> gnu.org (GNU bug Tracking System)
To: Michael Chapman <atat <at> mykolab.ch>
Subject: bug#35534: closed (Re: bug#35414: 26.2; ELPA packages signed with
 second, unknown key)
Date: Sat, 25 Jan 2020 17:32:02 +0000
[Message part 1 (text/plain, inline)]
Your bug report

#35414: 26.2; Failure to verify signature archive-contents.sig

which was filed against the emacs package, has been closed.

The explanation is attached below, along with your original report.
If you require more details, please reply to 35534 <at> debbugs.gnu.org.

-- 
35414: http://debbugs.gnu.org/cgi/bugreport.cgi?bug=35414
GNU Bug Tracking System
Contact help-debbugs <at> gnu.org with problems
[Message part 2 (message/rfc822, inline)]
From: Stefan Monnier <monnier <at> iro.umontreal.ca>
To: Stefan Kangas <stefan <at> marxist.se>
Cc: 35414-done <at> debbugs.gnu.org, Glenn Morris <rgm <at> gnu.org>,
 Brandon Invergo <brandon <at> invergo.net>
Subject: Re: bug#35414: 26.2; ELPA packages signed with second, unknown key
Date: Sat, 25 Jan 2020 12:31:21 -0500
> Is there anything more to do here, or should this bug be closed?

Done, thanks,


        Stefan


[Message part 3 (message/rfc822, inline)]
From: Michael Chapman <atat <at> mykolab.ch>
To: bug-gnu-emacs <at> gnu.org
Subject: 26.2; Failure to verify signature archive-contents.sig
Date: Thu, 02 May 2019 09:25:46 +0200
Hi all,

Bug symptom is triggered simply by

M-x package-list-packages RET
or
M-x list-packages RET

A buffer with a listing of packages opens, but then an *Error* buffer 
opens
with the following information:

Failed to verify signature archive-contents.sig:
Bad signature from 474F05837FBDEF9B GNU ELPA Signing Agent 
<elpasign <at> elpa.gnu.org>
Command output:
gpg: Signature made 05/01/19 23:10:02 W. Europe Daylight Time
gpg:                using DSA key 
CA442C00F91774F17F59D9B0474F05837FBDEF9B
gpg: BAD signature from "GNU ELPA Signing Agent <elpasign <at> elpa.gnu.org>" 
[unknown]

This is on a “fresh install” on Windows 10 after extracting from the zip 
archive
retrieved from
https://mirror.kumi.systems/gnu/emacs/windows/emacs-26/

Some further details of the context are available at
https://www.reddit.com/r/emacs/comments/bgdq2n/failure_to_install_auctex_on_emacs_with_package/
There I was advised this is a bug and should be reported.

Thanks and kind regards,
Mike

--

In GNU Emacs 26.2 (build 1, x86_64-w64-mingw32)
 of 2019-04-13 built on CIRROCUMULUS
Repository revision: fd1b34bfba8f3f6298df47c8e10b61530426f749
Windowing system distributor 'Microsoft Corp.', version 10.0.17134
Recent messages:
For information about GNU Emacs and the GNU system, type C-h C-a.
Making completion list...
Importing package-keyring.gpg...done
You can run the command ‘package-list-packages’ with M-x pa-l- RET
Package refresh done
error in process filter: package--check-signature-content: Failed to 
verify signature: "archive-contents.sig"
error in process filter: Failed to verify signature: 
"archive-contents.sig"

Configured using:
 'configure --without-dbus --host=x86_64-w64-mingw32
 --without-compress-install 'CFLAGS=-O2 -static -g3''

Configured features:
XPM JPEG TIFF GIF PNG RSVG SOUND NOTIFY ACL GNUTLS LIBXML2 ZLIB
TOOLKIT_SCROLL_BARS THREADS LCMS2

Important settings:
  value of $LANG: ENU
  locale-coding-system: cp1252

Major mode: Package Menu

Minor modes in effect:
  show-paren-mode: t
  tooltip-mode: t
  global-eldoc-mode: t
  electric-indent-mode: t
  mouse-wheel-mode: t
  tool-bar-mode: t
  menu-bar-mode: t
  file-name-shadow-mode: t
  global-font-lock-mode: t
  font-lock-mode: t
  blink-cursor-mode: t
  auto-composition-mode: t
  auto-encryption-mode: t
  auto-compression-mode: t
  buffer-read-only: t
  line-number-mode: t
  transient-mark-mode: t

Load-path shadows:
None found.

Features:
(shadow sort mail-extr emacsbug sendmail help-mode mm-archive message
dired dired-loaddefs format-spec rfc822 mml mml-sec epa derived
gnus-util rmail rmail-loaddefs mailabbrev gmm-utils mailheader mm-decode
mm-bodies mm-encode mail-utils network-stream starttls url-http tls
gnutls mail-parse rfc2231 rfc2047 rfc2045 mm-util ietf-drums mail-prsvr
url-gw nsm rmc puny url-cache url-auth url url-proxy url-privacy
url-expand url-methods url-history url-cookie url-domsuf url-util
mailcap epg elec-pair paren edmacro kmacro finder-inf package easymenu
epg-config url-handlers url-parse auth-source cl-seq eieio eieio-core
cl-macs eieio-loaddefs password-cache url-vars seq byte-opt gv bytecomp
byte-compile cconv cl-loaddefs cl-lib time-date mule-util tooltip eldoc
electric uniquify ediff-hook vc-hooks lisp-float-type mwheel dos-w32
ls-lisp disp-table term/w32-win w32-win w32-vars term/common-win
tool-bar dnd fontset image regexp-opt fringe tabulated-list replace
newcomment text-mode elisp-mode lisp-mode prog-mode register page
menu-bar rfn-eshadow isearch timer select scroll-bar mouse jit-lock
font-lock syntax facemenu font-core term/tty-colors frame cl-generic
cham georgian utf-8-lang misc-lang vietnamese tibetan thai tai-viet lao
korean japanese eucjp-ms cp51932 hebrew greek romanian slovak czech
european ethiopic indian cyrillic chinese composite charscript charprop
case-table epa-hook jka-cmpr-hook help simple abbrev obarray minibuffer
cl-preloaded nadvice loaddefs button faces cus-face macroexp files
text-properties overlay sha1 md5 base64 format env code-pages mule
custom widget hashtable-print-readable backquote threads w32notify w32
lcms2 multi-tty make-network-process emacs)

Memory information:
((conses 16 128540 11648)
 (symbols 48 22803 1)
 (miscs 40 96 163)
 (strings 32 37716 1313)
 (string-bytes 1 980407)
 (vectors 16 17445)
 (vector-slots 8 533882 9894)
 (floats 8 59 184)
 (intervals 56 2711 0)
 (buffers 992 15))



This bug report was last modified 4 years and 170 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.