You downloaded a vendor package and ran `rpm -K vendor-agent-3.2-1.x86_64.rpm`, which reported the digests as OK but the signature as NOKEY. What should you do to complete the verification?
LPIC-1 Exam 101-500, objective 102. Linux installation and package management hard
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Correct Import the vendor's public key with `rpm --import RPM-GPG-KEY-vendor`, then run rpm -K again
Correct. NOKEY means the package is signed but the signing key is not in the RPM keyring, so the signature cannot be checked. Importing the key and repeating the check turns the result into a signature OK, or exposes a genuine mismatch.
Not correct Install it with `rpm -Uvh --nosignature vendor-agent-3.2-1.x86_64.rpm`
Wrong. --nosignature suppresses the check rather than performing it, which is the opposite of verifying the package.
Not correct Run `rpm -V vendor-agent-3.2-1.x86_64.rpm`
Wrong. -V verifies files of an installed package against the RPM database; it is not a signature check and the package is not installed yet.
Not correct Set gpgcheck=0 in /etc/yum.conf
Wrong. That key controls signature checking for yum or dnf transactions, has no effect on a direct rpm -K, and again disables the check instead of satisfying it.
Why
rpm -K (--checksig) reports two independent things about a package file: the payload digests, which detect corruption in transit, and the OpenPGP signature, which proves who built it. A digests OK with signature NOKEY result therefore means the download is intact but unattributed. Keys are added to the rpm keyring with rpm --import and can be listed afterwards as pseudo-packages via `rpm -qa gpg-pubkey*`.
Where this comes from
- Cited
- manual page rpm(8)
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 102 and space the ones you get wrong.
More questions on this objective
- A mail server keeps filling its root filesystem because spooled mail and logs grow without bound, and when the disk fills the whole system becomes unusable. Which single change to the disk layout most directly contains that failure? machine-checked
- In LVM terminology, which object is created directly on a partition or whole disk so that its storage can be added to a pool? machine-checked
- You are laying out storage for a general-purpose Linux server. Which TWO of the following are genuine reasons to use LVM for the data filesystems rather than plain partitions? machine-checked
- Which file is the configuration file that GRUB 2 generates, and which administrators are told not to edit by hand on a typical Linux distribution? machine-checked
- You replaced the boot disk in a BIOS/MBR system and need to write the GRUB 2 boot loader into the master boot record of /dev/sda, installing the required GRUB modules under /boot. Which command does that? machine-checked
- On a GRUB 2 system whose configuration file is /boot/grub/grub.cfg, type the grub-mkconfig command — including the option and its argument — that regenerates that file. machine-checked