in reply to SOLVED: Key Not Certified in CPAN
I upgraded CPAN from 2.28 to 2.29
I refer you to the section on CPAN 2.29 is this summary of the fixes for last year's vulnerabilities.
🦛
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re^2: Key Not Certified in CPAN
by dorko (Prior) on Feb 24, 2022 at 22:45 UTC | |
Spot on. Thank you very much. I set check_sigs to 0 (ie false) in MyConfig.pm and modules are back to being installable again. But... That doesn't feel like the most secure thing in the world to be doing. Anyone with suggestions I can try to get the CHECKSUMS working? Cheers,
Brent
-- Yup, I'm a Delt.
| [reply] [d/l] [select] |
by pryrt (Abbot) on Feb 24, 2022 at 23:16 UTC | |
Anyone with suggestions I can try to get the CHECKSUMS working I don't use the default CPAN client. But the two suggestions I have:
However, I don't know that I'm convinced either of those will solve your problem: the message you quoted originally says that the actual CHECKSUMS file signature was okay; the problem it seemed to have was with opening a temporary CHECKSUMS.77905 file that wasn't there; I do not know what that file is, as compared to the CHECKSUMS file that was downloaded when you tried to get the package. I don't know whether doing the two above things will allow that temporary file to be correctly generated/extracted and thus allow the process to move forward. But since you were asking for any suggestions for things to try, I think this qualifies, fruitful or not ;-). | [reply] [d/l] |
by dorko (Prior) on Feb 25, 2022 at 16:07 UTC | |
I did spend a little time with it this morning. I imported two keys thusly: The keys are from https://pause.perl.org/pause/query?ACTION=pause_04about#pubkeybat as suggested by pryrt. I also did rm -rf /root/.cpan/CPAN/* to force new downloads of things (thank you Ken). Lastly I pointed my urllist to https://www.cpan.org/. (I previously had urllist pointed to an internal CPAN mirror on our network suggested to me by our networking / admin staff.) Despite those changes, I'm still seeing the "key not certified with a trusted signature" problem: And I agree the "could not open" error is problematic as well. I'm more than happy to switch check_sigs back to 0 and declare victory. If anyone has any other suggestions, I'm willing to tinker to see if I can get things working as we all know they could be. Thanks again. Cheers,
Brent
-- Yup, I'm a Delt.
| [reply] [d/l] [select] |