Today’s Tumbleweed snapshot 20260628 had an update for the openSUSE-build-key package.
That prompted me to check the current RPM Keyring for expired keys.
Opened Myrlyn – couldn’t find anything related to GPG Key management.
Checked the GitHub Myrlyn document – also nothing.
Checked the RPM CLI tools – I can list the details of the GPG Keys but, the expiration dates aren’t displayed.
Opened the YaST Repository Management and used that to clean up the Stygian Stables …
After Zypper “refresh --force” I rechecked the GPG Keys – yes there are still some expired GPG Keys reintroduced into the RPM Keyring –
security:keepassxc OBS Project
graphics OBS Project
69D1B2AAEE3D166A – security OBS Project – despite a newer key 5DA57BDD6DD785CA also being present …
openSUSE:Factory:zSystems OBS Project
9C214D4065176565 – openSUSE:Backports OBS Project – despite a newer key 8A49EB0325DB7AE0 also being present …
B88B2FD43DBDC284 – openSUSE Project Signing Key – despite a newer key 35A2F86E29B700A4 with a creation date of 28.05.2026 also being present …
openSUSE:Factory:PowerPC OBS Project
As you can see, keeping an eye on the RPM Keyring ain’t fun and, also, it ain’t funny …
Before YaST is finally killed off, is there any WIP to introduce RPM Keyring maintenance into Myrlyn?
Why is this in Open Chat ? There is no discussion here, it’s a simple support question, that would be fine in Install/Boot/Login IMHO. That said, there are already a number of threads about this, with proper solution.
Sorry but, searching for “Myrlyn” or/and “RPM Keyring” or/and “GPG Key” in Install/Boot/Login doesn’t, AFAICS, doesn’t find anything related to this issue.
AFAICS, none of the Posts related to Myrlyn in “Install/Boot/Login” have touched on the YaST capability to manage a machine’s (RPM) GPG Keys.
My Open Chat question remains:
Is there any Work In Progress to implement the YaST Repository Management “GPG Keys” feature in Myrlyn?
Where “sq” is the “Sequoia-sq” which is a frontend for the sequoia library used by RPM – <Keyring Management>
Extracting the PGP Public Key Block for a repository key with “rpm --query --info” doesn’t provide the format “sq inspect” wants and, the openSUSE/SUSE “rpmkeys” doesn’t provide an “export” option.
A DuckDuckGo search for “Linux RPM Keyring list expiry date” suggests the following AI result:
To check the expiry dates of GPG keys in the RPM Keyring, you can use the YaST Repository Management tool or the rpmkeys command to list the keys, but note that the expiration dates may not always be displayed directly. For detailed management, you may need to refer to specific documentation or tools related to your Linux distribution.
But, I’ll leave the Enhancement <Bug 1270093> Change Request open for the moment.
Did the exercise of –
# rpmkeys --delete ???-???
followed by –
# zypper refresh --force
Opposed to the method with YaST Repository Management “GPG Keys”, the duplicate expired Keys remain deleted and, the expired Key for the VLC openSUSE Repository (Dominique Leuenberger) has now been replaced by a Key due to expire 2026-10-22 …
Some musings why YaST has to be put out of its misery
Software archaeology uncovers some zombies lurking deep down in the basement:
(comment #7)
This is just scratching the surface. Digging just a little deeper might cause the Zombie Apocalypse.
If you have any comments about this specific part, please add them here in the forum, not in the GitHub issue; I’d like to keep that one on topic with the key managerment. TIA.
Stefan, I’ve reopened <Bug 1270093> with a request to document the RPM CLI commands needed to inspect a given system’s RPM GPG Keyring.
Specifically:
The RPM GPG Key Management for the case of Service Repositories (http://cdn.opensuse.org/) is fine - no issues.
The RPM GPG Key Management for the case of non-Service Repositories (Packman, KDE: Extra, GNOME: Next, etc, etc …) isn’t so wonderful.
There’s also the Use Case of “Commercial Repositories” - companies who offer commercial products for the openSUSE/SUSE platform …
The company “SoftMaker” «located not so many kilometres from SUSE’s Nürnberg office» offers a commercial Office suite and other products which execute on Linux – and other operating systems.
Stefan, thanks for accepting my reopened Request and, for reassigning it to the SUSE Security Team.
For those gentle readers who’re wondering about what’s going on here, a central point of RPM Repository Management is, the RPM GPG Keyring and, the Repository GPG Keys stored there.
If, the Keys are expired and/or outdated then, the trust in the RPM Repository disappears …