Skip to content

Can't boot Fedora ISOs : CHECKSUM files are not detached signed. #785

@tlaurion

Description

@tlaurion

From Fedora:

curl https://getfedora.org/static/fedora.gpg | gpg --import

  • The public key inside of Heads is still valid

gpg --verify-files *-CHECKSUM

gpg : Good signature from "Fedora (32) .... "
gpg: not a detached signature; file blahblah.iso was NOT verified

sha256sum -c *-CHECKSUM

sha256sum: WARNING: 21 of 21 computed checksums did NOT match while doing a sha256sum manually of the iso and comparing with the SHA256SUM file line shows the same hash obtained by validating manually fro command line...

What do we do with that?

@MrChromebox, any thoughts?
Not directly linked to #784 but this prohibited me to test directly your PR, since ISO boot was supposed to work. (Fedora, QubesOS and Tails can boot from iso if detached signed file is provided side by side with iso. No idea exactly when Fedora changed but even their archive repos have -CHECKSUM now and no .iso.asc nor .iso.sig.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions