I've been away for 2 weeks. I tried to do cert update, I have a new .fedora-upload-ca.cert dated 8/20.
I get: make tag build cvs tag -c mercurial-1_0_2-1_fc10 Permission denied (publickey). cvs [tag aborted]: end of file from server (consult above messages if any)
Neal Becker wrote:
I've been away for 2 weeks. I tried to do cert update, I have a new .fedora-upload-ca.cert dated 8/20.
I get: make tag build cvs tag -c mercurial-1_0_2-1_fc10 Permission denied (publickey). cvs [tag aborted]: end of file from server (consult above messages if any)
Did you upload a new ssh key to fas?
-- Rex
Rex Dieter wrote:
Neal Becker wrote:
I've been away for 2 weeks. I tried to do cert update, I have a new .fedora-upload-ca.cert dated 8/20.
I get: make tag build cvs tag -c mercurial-1_0_2-1_fc10 Permission denied (publickey). cvs [tag aborted]: end of file from server (consult above messages if any)
Did you upload a new ssh key to fas?
-- Rex
No. What do I need to do? (I use my rsa key for other purposes, so ssh-keygen -t rsa -b 2048
Upload the new public key (defaults to file ~/.ssh/id_rsa.pub).
is probably not what I want. Also, what does "upload the new public key" mean?
On Sun, Aug 24, 2008 at 10:03 PM, Neal Becker ndbecker2@gmail.com wrote:
Rex Dieter wrote:
Neal Becker wrote:
I've been away for 2 weeks. I tried to do cert update, I have a new .fedora-upload-ca.cert dated 8/20.
I get: make tag build cvs tag -c mercurial-1_0_2-1_fc10 Permission denied (publickey). cvs [tag aborted]: end of file from server (consult above messages if any)
Did you upload a new ssh key to fas?
-- Rex
No. What do I need to do? (I use my rsa key for other purposes, so ssh-keygen -t rsa -b 2048
Upload the new public key (defaults to file ~/.ssh/id_rsa.pub).
is probably not what I want. Also, what does "upload the new public key" mean?
Edit your profile at the FAS and upload your SSH public key. Many people have DSA keys and so they really have to create a new key and upload them. Even if you have an RSA key, all of contributors' public keys information were purged from the system (to make sure potentially compromised DSA keys are gone), so you'd still have to re-upload your (old) key anyway.
Michel Salim wrote:
On Sun, Aug 24, 2008 at 10:03 PM, Neal Becker ndbecker2@gmail.com wrote:
Rex Dieter wrote:
Neal Becker wrote:
I've been away for 2 weeks. I tried to do cert update, I have a new .fedora-upload-ca.cert dated 8/20.
I get: make tag build cvs tag -c mercurial-1_0_2-1_fc10 Permission denied (publickey). cvs [tag aborted]: end of file from server (consult above messages if any)
Did you upload a new ssh key to fas?
-- Rex
No. What do I need to do? (I use my rsa key for other purposes, so ssh-keygen -t rsa -b 2048
Upload the new public key (defaults to file ~/.ssh/id_rsa.pub).
is probably not what I want. Also, what does "upload the new public key" mean?
Edit your profile at the FAS and upload your SSH public key. Many people have DSA keys and so they really have to create a new key and upload them. Even if you have an RSA key, all of contributors' public keys information were purged from the system (to make sure potentially compromised DSA keys are gone), so you'd still have to re-upload your (old) key anyway.
OK, I uploaded a new RSA key. I still get the same thing: cvs -t tag -c mercurial-1_0_2-1_fc10 -> main loop with CVSROOT=:ext:nbecker@cvs.fedoraproject.org:/cvs/pkgs -> Starting server: ssh -l nbecker cvs.fedoraproject.org cvs server Permission denied (publickey). cvs [tag aborted]: end of file from server (consult above messages if any)
Hi Neal,
On Mon, Aug 25, 2008 at 4:35 PM, Neal Becker ndbecker2@gmail.com wrote:
Michel Salim wrote:
On Sun, Aug 24, 2008 at 10:03 PM, Neal Becker ndbecker2@gmail.com wrote:
Rex Dieter wrote:
Neal Becker wrote:
I've been away for 2 weeks. I tried to do cert update, I have a new .fedora-upload-ca.cert dated 8/20.
I get: make tag build cvs tag -c mercurial-1_0_2-1_fc10 Permission denied (publickey). cvs [tag aborted]: end of file from server (consult above messages if any)
Did you upload a new ssh key to fas?
-- Rex
No. What do I need to do? (I use my rsa key for other purposes, so ssh-keygen -t rsa -b 2048
Upload the new public key (defaults to file ~/.ssh/id_rsa.pub).
is probably not what I want. Also, what does "upload the new public key" mean?
Edit your profile at the FAS and upload your SSH public key. Many people have DSA keys and so they really have to create a new key and upload them. Even if you have an RSA key, all of contributors' public keys information were purged from the system (to make sure potentially compromised DSA keys are gone), so you'd still have to re-upload your (old) key anyway.
OK, I uploaded a new RSA key. I still get the same thing: cvs -t tag -c mercurial-1_0_2-1_fc10 -> main loop with CVSROOT=:ext:nbecker@cvs.fedoraproject.org:/cvs/pkgs -> Starting server: ssh -l nbecker cvs.fedoraproject.org cvs server Permission denied (publickey). cvs [tag aborted]: end of file from server (consult above messages if any)
I assume after uploading RSA keys you must have downloaded all 3 certs from folowing link again https://fedoraproject.org/wiki/PackageMaintainers/UsingKoji#Fedora_Certifica... If not then download again those certificates. also I guess you need to wait for 1 hour after uploading RSA keys.
Regards, Parag.
-- fedora-devel-list mailing list fedora-devel-list@redhat.com https://www.redhat.com/mailman/listinfo/fedora-devel-list
"NB" == Neal Becker writes:
[...]
NB> OK, I uploaded a new RSA key. I still get the same thing: NB> cvs -t tag -c mercurial-1_0_2-1_fc10 -> main loop with CVSROOT=:ext:nbecker@cvs.fedoraproject.org:/cvs/pkgs -> Starting server: ssh -l nbecker cvs.fedoraproject.org cvs server NB> Permission denied (publickey). cvs [tag aborted]: end of file NB> from server (consult above messages if any)
It can take up to an hour or more (in my case it was at least 1.5 hours) before the servers update with the new keys. I ended up coming back after several hours and it all worked after that.
Alex
Neal Becker ndbecker2@gmail.com writes:
I've been away for 2 weeks. I tried to do cert update, I have a new .fedora-upload-ca.cert dated 8/20. I get: make tag build cvs tag -c mercurial-1_0_2-1_fc10 Permission denied (publickey).
Not an expert, but this looks what I got before I re-uploaded my ssh key: https://fedoraproject.org/wiki/Infrastructure/ReplacingSSHKey (If you have any reason at all to think that your ssh key was compromised, better make a new one first.)
Also, have you done *all* the steps mentioned here: https://www.redhat.com/archives/fedora-devel-announce/2008-August/msg00008.h...
(The browser import part might not be relevant, but the rest definitely are.)
regards, tom lane