[Owasp-modsecurity-core-rule-set] Problem with package signature

Majed B. majedb at gmail.com
Wed Aug 17 10:22:56 EDT 2011


Hello everyone,

I'm setting up the ruler-updater to auto download and unpack the latest
stable but I'm having a problem with the signature.

rules-updater.pl -c rules-updater.conf -Smodsecurity-crs
Fetching: modsecurity-crs/modsecurity-crs_2.2.1.zip ...
Verifying
"/etc/apache2/mods-available/mod-security/modsecurity-crs/modsecurity-crs_2.2.1.zip"
with signature
"/etc/apache2/mods-available/mod-security/modsecurity-crs/modsecurity-crs_2.2.1.zip.sig"
Signature made Wed Jul 20 20:42:26 2011 by Ryan Barnett (OWASP Core Rule Set
Project Leader) <rbarnett at trustwave.com> (ID: C976607D9624FCD2) and is not
trusted.
Signature is not trusted fully.

I imported the key into gpg and signed it locally: gpg --lsign-key
0xC976607D9624FCD2, but still get the error above.

Any hints on this?

Thank you.
-- 
       Majed B.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: https://lists.owasp.org/pipermail/owasp-modsecurity-core-rule-set/attachments/20110817/703530c5/attachment-0001.html 


More information about the Owasp-modsecurity-core-rule-set mailing list