You downloaded a vendor package and ran `rpm -K vendor-agent-3.2-1.x86_64.rpm`, which reported the digests as OK but the signature as NOKEY. What should you do to complete the verification?

LPIC-1 Exam 101-500, objective 102. Linux installation and package management hard

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Correct Import the vendor's public key with `rpm --import RPM-GPG-KEY-vendor`, then run rpm -K again

Correct. NOKEY means the package is signed but the signing key is not in the RPM keyring, so the signature cannot be checked. Importing the key and repeating the check turns the result into a signature OK, or exposes a genuine mismatch.

Not correct Install it with `rpm -Uvh --nosignature vendor-agent-3.2-1.x86_64.rpm`

Wrong. --nosignature suppresses the check rather than performing it, which is the opposite of verifying the package.

Not correct Run `rpm -V vendor-agent-3.2-1.x86_64.rpm`

Wrong. -V verifies files of an installed package against the RPM database; it is not a signature check and the package is not installed yet.

Not correct Set gpgcheck=0 in /etc/yum.conf

Wrong. That key controls signature checking for yum or dnf transactions, has no effect on a direct rpm -K, and again disables the check instead of satisfying it.

Why

rpm -K (--checksig) reports two independent things about a package file: the payload digests, which detect corruption in transit, and the OpenPGP signature, which proves who built it. A digests OK with signature NOKEY result therefore means the download is intact but unattributed. Keys are added to the rpm keyring with rpm --import and can be listed afterwards as pseudo-packages via `rpm -qa gpg-pubkey*`.

Where this comes from

Cited
manual page rpm(8)

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 102 and space the ones you get wrong.

Practise LPIC-1 Exam 101-500

More questions on this objective

All questions on Linux installation and package management

Practise LPIC-1 Exam 101-500