Lately I’ve been getting this error when I run zypper dup:
sudo zypper dup
Signature verification failed for file ‘repomd.xml’ from repository ‘Main Repository (NON-OSS)’.
Note: Signing data enables the recipient to verify that no modifications occurred after the data
were signed. Accepting data with no, wrong or unknown signature can lead to a corrupted system
and in extreme cases even to a system compromise.
Note: File 'repomd.xml' is the repositories master index file. It ensures the integrity of the
whole repo.
Warning: This file was modified after it has been signed. This may have been a malicious change,
so it might not be trustworthy anymore! You should not continue unless you know it's safe.
Is it safe to ignore this error? For what it’s worth, I’m using repos from https://mirrorcache-us. Does that make a difference?
Thanks for checking. I waited a while and tried again without any errors. But that error seems to happen randomly, so I guess for safety I should abort and try again later.