{"id":5679,"date":"2023-02-16T15:13:36","date_gmt":"2023-02-16T09:43:36","guid":{"rendered":"https:\/\/trysiteprice.com\/blog\/?p=5679"},"modified":"2023-02-16T15:13:36","modified_gmt":"2023-02-16T09:43:36","slug":"centos-redhat-protect-yum-repos-packages","status":"publish","type":"post","link":"https:\/\/trysiteprice.com\/blog\/centos-redhat-protect-yum-repos-packages\/","title":{"rendered":"CentOS \/ Redhat: Protect Yum Repo&#8217;s Packages"},"content":{"rendered":"<p>To protect the packages in your Yum repositories on CentOS\/Redhat, you can use GPG (GNU Privacy Guard) to sign the RPM packages and verify their signatures before installing them. Here are the steps:<\/p>\n<ol>\n<li>Install the necessary packages to support GPG signing and verification:<\/li>\n<\/ol>\n<div class=\"bg-black mb-4 rounded-md\">\n<div class=\"flex items-center relative text-gray-200 bg-gray-800 px-4 py-2 text-xs font-sans\"><\/div>\n<div class=\"p-4 overflow-y-auto\"><code class=\"!whitespace-pre hljs\">sudo yum install gnupg2<br \/>\n<\/code><\/div>\n<\/div>\n<ol start=\"2\">\n<li>Generate a GPG key pair that will be used to sign packages. You can do this by running the following command:<\/li>\n<\/ol>\n<div class=\"bg-black mb-4 rounded-md\">\n<div class=\"flex items-center relative text-gray-200 bg-gray-800 px-4 py-2 text-xs font-sans\"><\/div>\n<div class=\"p-4 overflow-y-auto\"><code class=\"!whitespace-pre hljs language-css\">gpg2 <span class=\"hljs-attr\">--gen-key<\/span><br \/>\n<\/code><\/div>\n<\/div>\n<p>Follow the prompts to generate a new key pair. Be sure to choose a strong passphrase for your key.<\/p>\n<ol start=\"3\">\n<li>Export the public key for your GPG key pair, which will be used to verify the signature on packages. You can do this by running the following command:<\/li>\n<\/ol>\n<div class=\"bg-black mb-4 rounded-md\">\n<div class=\"flex items-center relative text-gray-200 bg-gray-800 px-4 py-2 text-xs font-sans\"><\/div>\n<div class=\"p-4 overflow-y-auto\"><code class=\"!whitespace-pre hljs language-css\">gpg2 <span class=\"hljs-attr\">--export<\/span> <span class=\"hljs-attr\">--armor<\/span> &lt;KEY_ID&gt; &gt; mykey<span class=\"hljs-selector-class\">.asc<\/span><br \/>\n<\/code><\/div>\n<\/div>\n<p>Replace <code>&lt;KEY_ID&gt;<\/code> with the ID of the GPG key you generated in step 2.<\/p>\n<ol start=\"4\">\n<li>Copy the <code>mykey.asc<\/code> file to the Yum repository&#8217;s GPG keyring directory:<\/li>\n<\/ol>\n<div class=\"bg-black mb-4 rounded-md\">\n<div class=\"flex items-center relative text-gray-200 bg-gray-800 px-4 py-2 text-xs font-sans\"><\/div>\n<div class=\"p-4 overflow-y-auto\"><code class=\"!whitespace-pre hljs language-bash\">sudo <span class=\"hljs-built_in\">cp<\/span> mykey.asc \/etc\/pki\/rpm-gpg\/<br \/>\n<\/code><\/div>\n<\/div>\n<ol start=\"5\">\n<li>Create a new Yum repository configuration file (if one does not already exist) in the <code>\/etc\/yum.repos.d\/<\/code> directory. For example, you could create a file called <code>myrepo.repo<\/code> with the following contents:<\/li>\n<\/ol>\n<div class=\"bg-black mb-4 rounded-md\">\n<div class=\"flex items-center relative text-gray-200 bg-gray-800 px-4 py-2 text-xs font-sans\"><\/div>\n<div class=\"p-4 overflow-y-auto\"><code class=\"!whitespace-pre hljs language-makefile\">[myrepo]<br \/>\nname=My Repository<br \/>\nbaseurl=http:\/\/example.com\/myrepo<br \/>\ngpgcheck=1<br \/>\ngpgkey=file:\/\/\/etc\/pki\/rpm-gpg\/mykey.asc<br \/>\n<\/code><\/div>\n<\/div>\n<p>This tells Yum to check for a signature on all packages installed from the <code>myrepo<\/code> repository, and to use the GPG key located at <code>\/etc\/pki\/rpm-gpg\/mykey.asc<\/code> to verify the signature.<\/p>\n<ol start=\"6\">\n<li>Import the public key for any third-party repositories that you want to trust. For example, to import the EPEL repository&#8217;s key, you can run the following command:<\/li>\n<\/ol>\n<div class=\"bg-black mb-4 rounded-md\">\n<div class=\"flex items-center relative text-gray-200 bg-gray-800 px-4 py-2 text-xs font-sans\"><\/div>\n<div class=\"p-4 overflow-y-auto\"><code class=\"!whitespace-pre hljs language-javascript\">sudo rpm --<span class=\"hljs-keyword\">import<\/span> <span class=\"hljs-attr\">https<\/span>:<span class=\"hljs-comment\">\/\/dl.fedoraproject.org\/pub\/epel\/RPM-GPG-KEY-EPEL-7<\/span><br \/>\n<\/code><\/div>\n<\/div>\n<p>This imports the EPEL repository&#8217;s key into your system&#8217;s GPG keyring so that you can verify the signature on packages installed from the EPEL repository.<\/p>\n<p>That&#8217;s it! With GPG signing and verification in place, Yum will only install packages from trusted repositories with valid signatures. If a package has been tampered with, its signature will not match and Yum will refuse to install it.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>To protect the packages in your Yum repositories on CentOS\/Redhat, you can use GPG (GNU Privacy Guard) to sign the RPM packages and verify their signatures before installing them. Here are the steps: Install the necessary packages to support GPG signing and verification: sudo yum install gnupg2 Generate a GPG key pair that will be &#8230; <a title=\"CentOS \/ Redhat: Protect Yum Repo&#8217;s Packages\" class=\"read-more\" href=\"https:\/\/trysiteprice.com\/blog\/centos-redhat-protect-yum-repos-packages\/\" aria-label=\"Read more about CentOS \/ Redhat: Protect Yum Repo&#8217;s Packages\">Read more<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-5679","post","type-post","status-publish","format-standard","hentry","category-best-tutorial"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>CentOS \/ Redhat: Protect Yum Repo&#039;s Packages - TrySitePrice<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trysiteprice.com\/blog\/centos-redhat-protect-yum-repos-packages\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"CentOS \/ Redhat: Protect Yum Repo&#039;s Packages - TrySitePrice\" \/>\n<meta property=\"og:description\" content=\"To protect the packages in your Yum repositories on CentOS\/Redhat, you can use GPG (GNU Privacy Guard) to sign the RPM packages and verify their signatures before installing them. Here are the steps: Install the necessary packages to support GPG signing and verification: sudo yum install gnupg2 Generate a GPG key pair that will be ... Read more\" \/>\n<meta property=\"og:url\" content=\"https:\/\/trysiteprice.com\/blog\/centos-redhat-protect-yum-repos-packages\/\" \/>\n<meta property=\"og:site_name\" content=\"TrySitePrice\" \/>\n<meta property=\"article:published_time\" content=\"2023-02-16T09:43:36+00:00\" \/>\n<meta name=\"author\" content=\"Rahul Sahu\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/trysiteprice.com\/blog\/centos-redhat-protect-yum-repos-packages\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/trysiteprice.com\/blog\/centos-redhat-protect-yum-repos-packages\/\"},\"author\":{\"name\":\"Rahul Sahu\",\"@id\":\"https:\/\/trysiteprice.com\/blog\/#\/schema\/person\/358e04eeea4281deacad2f30c58e67f4\"},\"headline\":\"CentOS \/ Redhat: Protect Yum Repo&#8217;s Packages\",\"datePublished\":\"2023-02-16T09:43:36+00:00\",\"dateModified\":\"2023-02-16T09:43:36+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/trysiteprice.com\/blog\/centos-redhat-protect-yum-repos-packages\/\"},\"wordCount\":286,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/trysiteprice.com\/blog\/#organization\"},\"articleSection\":[\"Best\/Tutorial\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/trysiteprice.com\/blog\/centos-redhat-protect-yum-repos-packages\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/trysiteprice.com\/blog\/centos-redhat-protect-yum-repos-packages\/\",\"url\":\"https:\/\/trysiteprice.com\/blog\/centos-redhat-protect-yum-repos-packages\/\",\"name\":\"CentOS \/ Redhat: Protect Yum Repo's Packages - TrySitePrice\",\"isPartOf\":{\"@id\":\"https:\/\/trysiteprice.com\/blog\/#website\"},\"datePublished\":\"2023-02-16T09:43:36+00:00\",\"dateModified\":\"2023-02-16T09:43:36+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/trysiteprice.com\/blog\/centos-redhat-protect-yum-repos-packages\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/trysiteprice.com\/blog\/centos-redhat-protect-yum-repos-packages\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/trysiteprice.com\/blog\/centos-redhat-protect-yum-repos-packages\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/trysiteprice.com\/blog\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"CentOS \/ Redhat: Protect Yum Repo&#8217;s Packages\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/trysiteprice.com\/blog\/#website\",\"url\":\"https:\/\/trysiteprice.com\/blog\/\",\"name\":\"TrySitePrice\",\"description\":\"Free Website Value Calculator Tool\",\"publisher\":{\"@id\":\"https:\/\/trysiteprice.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/trysiteprice.com\/blog\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/trysiteprice.com\/blog\/#organization\",\"name\":\"TrySitePrice\",\"url\":\"https:\/\/trysiteprice.com\/blog\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/trysiteprice.com\/blog\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/trysiteprice.com\/blog\/wp-content\/uploads\/2021\/12\/cropped-trysiteprice-logo.png\",\"contentUrl\":\"https:\/\/trysiteprice.com\/blog\/wp-content\/uploads\/2021\/12\/cropped-trysiteprice-logo.png\",\"width\":395,\"height\":268,\"caption\":\"TrySitePrice\"},\"image\":{\"@id\":\"https:\/\/trysiteprice.com\/blog\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/trysiteprice.com\/blog\/#\/schema\/person\/358e04eeea4281deacad2f30c58e67f4\",\"name\":\"Rahul Sahu\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/trysiteprice.com\/blog\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/51f0f95f7b95665f62baed2211572165?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/51f0f95f7b95665f62baed2211572165?s=96&d=mm&r=g\",\"caption\":\"Rahul Sahu\"},\"sameAs\":[\"https:\/\/trysiteprice.com\/blog\"],\"url\":\"https:\/\/trysiteprice.com\/blog\/author\/rsahu4242_trysiteprice\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"CentOS \/ Redhat: Protect Yum Repo's Packages - TrySitePrice","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trysiteprice.com\/blog\/centos-redhat-protect-yum-repos-packages\/","og_locale":"en_US","og_type":"article","og_title":"CentOS \/ Redhat: Protect Yum Repo's Packages - TrySitePrice","og_description":"To protect the packages in your Yum repositories on CentOS\/Redhat, you can use GPG (GNU Privacy Guard) to sign the RPM packages and verify their signatures before installing them. Here are the steps: Install the necessary packages to support GPG signing and verification: sudo yum install gnupg2 Generate a GPG key pair that will be ... Read more","og_url":"https:\/\/trysiteprice.com\/blog\/centos-redhat-protect-yum-repos-packages\/","og_site_name":"TrySitePrice","article_published_time":"2023-02-16T09:43:36+00:00","author":"Rahul Sahu","twitter_card":"summary_large_image","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/trysiteprice.com\/blog\/centos-redhat-protect-yum-repos-packages\/#article","isPartOf":{"@id":"https:\/\/trysiteprice.com\/blog\/centos-redhat-protect-yum-repos-packages\/"},"author":{"name":"Rahul Sahu","@id":"https:\/\/trysiteprice.com\/blog\/#\/schema\/person\/358e04eeea4281deacad2f30c58e67f4"},"headline":"CentOS \/ Redhat: Protect Yum Repo&#8217;s Packages","datePublished":"2023-02-16T09:43:36+00:00","dateModified":"2023-02-16T09:43:36+00:00","mainEntityOfPage":{"@id":"https:\/\/trysiteprice.com\/blog\/centos-redhat-protect-yum-repos-packages\/"},"wordCount":286,"commentCount":0,"publisher":{"@id":"https:\/\/trysiteprice.com\/blog\/#organization"},"articleSection":["Best\/Tutorial"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/trysiteprice.com\/blog\/centos-redhat-protect-yum-repos-packages\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/trysiteprice.com\/blog\/centos-redhat-protect-yum-repos-packages\/","url":"https:\/\/trysiteprice.com\/blog\/centos-redhat-protect-yum-repos-packages\/","name":"CentOS \/ Redhat: Protect Yum Repo's Packages - TrySitePrice","isPartOf":{"@id":"https:\/\/trysiteprice.com\/blog\/#website"},"datePublished":"2023-02-16T09:43:36+00:00","dateModified":"2023-02-16T09:43:36+00:00","breadcrumb":{"@id":"https:\/\/trysiteprice.com\/blog\/centos-redhat-protect-yum-repos-packages\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trysiteprice.com\/blog\/centos-redhat-protect-yum-repos-packages\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/trysiteprice.com\/blog\/centos-redhat-protect-yum-repos-packages\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/trysiteprice.com\/blog\/"},{"@type":"ListItem","position":2,"name":"CentOS \/ Redhat: Protect Yum Repo&#8217;s Packages"}]},{"@type":"WebSite","@id":"https:\/\/trysiteprice.com\/blog\/#website","url":"https:\/\/trysiteprice.com\/blog\/","name":"TrySitePrice","description":"Free Website Value Calculator Tool","publisher":{"@id":"https:\/\/trysiteprice.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trysiteprice.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/trysiteprice.com\/blog\/#organization","name":"TrySitePrice","url":"https:\/\/trysiteprice.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/trysiteprice.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/trysiteprice.com\/blog\/wp-content\/uploads\/2021\/12\/cropped-trysiteprice-logo.png","contentUrl":"https:\/\/trysiteprice.com\/blog\/wp-content\/uploads\/2021\/12\/cropped-trysiteprice-logo.png","width":395,"height":268,"caption":"TrySitePrice"},"image":{"@id":"https:\/\/trysiteprice.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/trysiteprice.com\/blog\/#\/schema\/person\/358e04eeea4281deacad2f30c58e67f4","name":"Rahul Sahu","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/trysiteprice.com\/blog\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/51f0f95f7b95665f62baed2211572165?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/51f0f95f7b95665f62baed2211572165?s=96&d=mm&r=g","caption":"Rahul Sahu"},"sameAs":["https:\/\/trysiteprice.com\/blog"],"url":"https:\/\/trysiteprice.com\/blog\/author\/rsahu4242_trysiteprice\/"}]}},"_links":{"self":[{"href":"https:\/\/trysiteprice.com\/blog\/wp-json\/wp\/v2\/posts\/5679","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trysiteprice.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/trysiteprice.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/trysiteprice.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/trysiteprice.com\/blog\/wp-json\/wp\/v2\/comments?post=5679"}],"version-history":[{"count":1,"href":"https:\/\/trysiteprice.com\/blog\/wp-json\/wp\/v2\/posts\/5679\/revisions"}],"predecessor-version":[{"id":5682,"href":"https:\/\/trysiteprice.com\/blog\/wp-json\/wp\/v2\/posts\/5679\/revisions\/5682"}],"wp:attachment":[{"href":"https:\/\/trysiteprice.com\/blog\/wp-json\/wp\/v2\/media?parent=5679"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/trysiteprice.com\/blog\/wp-json\/wp\/v2\/categories?post=5679"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/trysiteprice.com\/blog\/wp-json\/wp\/v2\/tags?post=5679"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}