infra-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Brian Fox (JIRA)" <j...@apache.org>
Subject [jira] [Comment Edited] (INFRA-18018) Failed to validate the pgp signature of .... check the logs.
Date Tue, 19 Mar 2019 19:49:00 GMT

    [ https://issues.apache.org/jira/browse/INFRA-18018?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16796458#comment-16796458
] 

Brian Fox edited comment on INFRA-18018 at 3/19/19 7:48 PM:
------------------------------------------------------------

I think the timeouts are somewhat unrelated, this appears to be the actual issue, what kind
of key did you create?

2019-03-19 19:36:27 DEBUG [pool-1-thread-2] - com.sonatype.nexus.pgp.DefaultPGPKeyManager
- Internal error while checking signature for artifact: "/org/apache/spark/spark-network-shuffle_2.12/2.4.1/spark-network-shuffle_2.12-2.4.1-test-sources.jar".
com.sonatype.mercury.plexus.pgp.PgpVerifierException: java.io.IOException: unknown signature
key algorithm: 19
	at com.sonatype.mercury.plexus.pgp.DefaultPgpVerifier$Cage.getKeyRing(DefaultPgpVerifier.java:212)



was (Author: brianf):
I think the timeouts are somewhat unrelated, this appears to be the actual issue, what kind
of key did you create?

2019-03-19 19:36:27 DEBUG [pool-1-thread-2] - com.sonatype.nexus.pgp.DefaultPGPKeyManager
- Internal error while checking signature for artifact: "/org/apache/spark/spark-network-shuffle_2.12/2.4.1/spark-network-shuffle_2.12-2.4.1-test-sources.jar".
com.sonatype.mercury.plexus.pgp.PgpVerifierException: java.io.IOException: unknown signature
key algorithm: 19
	at com.sonatype.mercury.plexus.pgp.DefaultPgpVerifier$Cage.getKeyRing(DefaultPgpVerifier.java:212)
	at com.sonatype.mercury.plexus.pgp.DefaultPgpVerifier$Cage.access$000(DefaultPgpVerifier.java:82)
	at com.sonatype.mercury.plexus.pgp.DefaultPgpVerifier.getKeyRingsFromRemote(DefaultPgpVerifier.java:412)
	at com.sonatype.mercury.plexus.pgp.DefaultPgpVerifier.addKeys(DefaultPgpVerifier.java:253)
	at com.sonatype.mercury.plexus.pgp.DefaultPgpVerifier.verify(DefaultPgpVerifier.java:324)
	at com.sonatype.nexus.pgp.DefaultPGPKeyManager.validateSignature(DefaultPGPKeyManager.java:150)
	at com.sonatype.nexus.pgp.DefaultPGPKeyManager.validateSignature(DefaultPGPKeyManager.java:287)
	at com.sonatype.nexus.staging.internal.rules.SignatureStagingRuleEvaluator$SignatureRuleWalkerProcessor.processFileItem(SignatureStagingRuleEvaluator.java:95)
	at org.sonatype.nexus.proxy.walker.AbstractFileWalkerProcessor.processItem(AbstractFileWalkerProcessor.java:26)
	at org.sonatype.nexus.proxy.walker.DefaultWalker.processItem(DefaultWalker.java:292)
	at org.sonatype.nexus.proxy.walker.DefaultWalker.walkItem(DefaultWalker.java:244)
	at org.sonatype.nexus.proxy.walker.DefaultWalker.walkRecursive(DefaultWalker.java:200)
	at org.sonatype.nexus.proxy.walker.DefaultWalker.walkRecursive(DefaultWalker.java:209)
	at org.sonatype.nexus.proxy.walker.DefaultWalker.walkRecursive(DefaultWalker.java:209)
	at org.sonatype.nexus.proxy.walker.DefaultWalker.walkRecursive(DefaultWalker.java:209)
	at org.sonatype.nexus.proxy.walker.DefaultWalker.walkRecursive(DefaultWalker.java:209)
	at org.sonatype.nexus.proxy.walker.DefaultWalker.walkRecursive(DefaultWalker.java:209)
	at org.sonatype.nexus.proxy.walker.DefaultWalker.walk(DefaultWalker.java:89)
	at com.sonatype.nexus.staging.rule.AbstractStagingRuleEvaluator.evaluate(AbstractStagingRuleEvaluator.java:47)
	at com.sonatype.nexus.staging.rule.StagingRule.evaluate(StagingRule.java:63)
	at com.sonatype.nexus.staging.internal.StagingRulesHelper.evaluateRules(StagingRulesHelper.java:271)
	at com.sonatype.nexus.staging.internal.StagingRulesHelper.evaluateRuleSet(StagingRulesHelper.java:238)
	at com.sonatype.nexus.staging.internal.StagingRulesHelper.evaluateProfileRuleSets(StagingRulesHelper.java:131)
	at com.sonatype.nexus.staging.internal.StagingRulesHelper.evaluate(StagingRulesHelper.java:102)
	at com.sonatype.nexus.staging.internal.task.RepositoryCloseTask$CloseOperation.verifyItem(RepositoryCloseTask.java:89)
	at com.sonatype.nexus.staging.internal.task.RepositoryCloseTask$CloseOperation.verifyItem(RepositoryCloseTask.java:1)
	at com.sonatype.nexus.staging.internal.task.OperationTaskSupport$OperationSupport.verify(OperationTaskSupport.java:302)
	at com.sonatype.nexus.staging.internal.task.OperationTaskSupport.executeOperations(OperationTaskSupport.java:438)
	at com.sonatype.nexus.staging.internal.task.OperationTaskSupport.doCall(OperationTaskSupport.java:428)
	at com.sonatype.nexus.staging.internal.task.TaskSupport.call(TaskSupport.java:37)
	at com.sonatype.nexus.staging.internal.task.StagingTaskSupport.call(StagingTaskSupport.java:133)
	at com.sonatype.nexus.staging.internal.task.StagingBackgroundTask.execute(StagingBackgroundTask.java:67)
	at com.sonatype.nexus.staging.internal.task.NexusTaskSupport.doRun(NexusTaskSupport.java:52)
	at com.sonatype.nexus.staging.internal.task.NexusTaskSupport.doRun(NexusTaskSupport.java:1)
	at org.sonatype.nexus.scheduling.AbstractNexusTask.call(AbstractNexusTask.java:163)
	at org.sonatype.scheduling.DefaultScheduledTask.call(DefaultScheduledTask.java:418)
	at org.sonatype.nexus.threads.MDCAwareCallable.call(MDCAwareCallable.java:44)
	at org.apache.shiro.subject.support.SubjectCallable.doCall(SubjectCallable.java:90)
	at org.apache.shiro.subject.support.SubjectCallable.call(SubjectCallable.java:83)
	at java.util.concurrent.FutureTask.run(FutureTask.java:266)
	at java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.access$201(ScheduledThreadPoolExecutor.java:180)
	at java.util.concurrent.ScheduledThreadPoolExecutor$ScheduledFutureTask.run(ScheduledThreadPoolExecutor.java:293)
	at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)
	at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)
	at java.lang.Thread.run(Thread.java:748)
Caused by: java.io.IOException: unknown signature key algorithm: 19
	at org.bouncycastle.bcpg.SignaturePacket.<init>(Unknown Source)
	at org.bouncycastle.bcpg.BCPGInputStream.readPacket(Unknown Source)
	at org.bouncycastle.openpgp.PGPKeyRing.readSignaturesAndTrust(Unknown Source)
	at org.bouncycastle.openpgp.PGPKeyRing.readUserIDs(Unknown Source)
	at org.bouncycastle.openpgp.PGPPublicKeyRing.<init>(Unknown Source)
	at org.bouncycastle.openpgp.PGPPublicKeyRing.<init>(Unknown Source)
	at com.sonatype.mercury.plexus.pgp.DefaultPgpVerifier$Cage.getKeyRing(DefaultPgpVerifier.java:209)
	... 44 common frames omitted

> Failed to validate the pgp signature of .... check the logs.
> ------------------------------------------------------------
>
>                 Key: INFRA-18018
>                 URL: https://issues.apache.org/jira/browse/INFRA-18018
>             Project: Infrastructure
>          Issue Type: Improvement
>          Components: Nexus
>            Reporter: DB Tsai
>            Assignee: Chris Lambertus
>            Priority: Major
>
> I am trying to create a new release of Spark 2.4.1, and I often run into "Failed to validate
the pgp signature" when I upload the artifacts to Nexus. It's intermittent, and doesn't happen
every time, but it happens very often that I need to rebuild the release many times to get
one successful upload. My key is in key server  42E5B25A8F7A82C1. Can any admin check the
log on Nexus side, and see what's going on? 
> BTW, I downloaded the jars and asc; I manually checked the signature locally, and they
all looked good. See orgapachespark-1313
> Thanks.



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

Mime
View raw message