Describe the issue In the RHEL 8 repo the repmod.xml.asc file is missing so dnf configured for repo_gpgcheck causes dnf to return a 404 error when doing a makecache
When do you need this? (YYYY/MM/DD) 2025-06-04 16:00 MST
When is this no longer needed or useful? (YYYY/MM/DD) N/A
If we cannot complete your request, what is the impact? I am unable to configure a Rocky system with CIS hardening that uses EPEL
# dnf makecache Rocky Linux 8 - AppStream 297 kB/s | 18 MB 01:02 Rocky Linux 8 - BaseOS 409 kB/s | 25 MB 01:02 Rocky Linux 8 - Extras 248 B/s | 15 kB 01:00 Extra Packages for Enterprise Linux 8 - x86_64 6.4 B/s | 196 B 00:30 Extra Packages for Enterprise Linux 8 - x86_64 1.6 MB/s | 1.6 kB 00:00 Extra Packages for Enterprise Linux 8 - x86_64 6.4 B/s | 196 B 00:30 Errors during downloading metadata for repository 'epel': - Curl error (28): Timeout was reached for https://mirror.cpsc.ucalgary.ca/mirror/fedora-epel/8/Everything/x86_64/repodata/repomd.xml [Connection timed out after 30000 milliseconds] - Status code: 404 for http://dl.fedoraproject.org/pub/epel/8/Everything/x86_64/repodata/repomd.xml.asc (IP: 38.145.60.24) - Status code: 404 for http://dl.fedoraproject.org/pub/epel/8/Everything/x86_64/repodata/repomd.xml.asc (IP: 38.145.60.22) Error: Failed to download metadata for repo 'epel': GPG verification is enabled, but GPG signature is not available. This may be an error or the repository does not support GPG verification: Status code: 404 for http://dl.fedoraproject.org/pub/epel/8/Everything/x86_64/repodata/repomd.xml.asc (IP: 38.145.60.22)
Fedora is currently unable to sign repository metadata, so anything that requires it as part of security hardening will require exceptions from your auditors.
Metadata Update from @james: - Issue close_status updated to: Can't Fix - Issue status updated to: Closed (was: Open) - Issue tagged with: high-trouble, medium-gain