The dnf Signature Check That Is Off By Default
dnf checks the signature on a package it downloads and not on one you hand it: localpkg_gpgcheck is absent from dnf.conf and defaults to off, and so is repo_gpgcheck. This role sets both and proves each by what it prevents, refusing an unsigned package and an unsigned repository it builds, then checking the distribution's repositories still verify. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-09-27 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-dnf-security?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [The dnf Signature Check That Is Off By Default](https://www.iac-bazaar.com/catalog/ansible-dnf-security?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# The dnf Signature Check That Is Off By Default: https://www.iac-bazaar.com/catalog/ansible-dnf-security (download from your IaC Bazaar account)
```Preview:
Documentation
dnf-security
dnf checks the signature on a package it downloads, and not on one you hand
it. gpgcheck=1 is in the shipped configuration; localpkg_gpgcheck is not in
it at all and defaults to off, so dnf install ./something.rpm installs an
unsigned package without a word. repo_gpgcheck is missing the same way, which
leaves a repository's metadata unverified. This role sets all three and proves
each by the thing it is supposed to prevent.
No download, and no version to pin. dnf is the distribution. What the role
owns is four lines in /etc/dnf/dnf.conf - dnf 4, which is what EL 10 carries,
has no drop-in directory for them - and the proof that the host now refuses what
it used to accept.
A repository file can opt itself out, and that beats dnf.conf. Measured
both ways: a repository asking for repo_gpgcheck=1 was honoured against a
[main] that said 0, and a repository setting gpgcheck=0 keeps its own answer.
The role does not rewrite anybody else's repository file - it names the ones that
opt out and stops, which is dnf_security_fail_on_unchecked_repos.
rpm -K exits 0 on a completely unsigned package. On the fixture this
role's test builds, rpm -Kv lists four digests, no signature, and returns
success; rpm -qpi says Signature : (none). Anything that treats rpm -K as a
signature check is reading a digest as a provenance claim, which is why the live
test asserts the fixture is unsigned through the signature header before it
draws any conclusion from dnf's refusal.
dnf config-manager --dump is dnf's sshd -T. It prints the configuration
dnf will use, defaults included, which is what the test reads. The obvious
alternative does not work: python3 -c "import dnf; dnf.Base().conf.localpkg_gpgcheck"
answered False for all three booleans against a dnf.conf that said 1, and
answered gpgcheck=False against a shipped gpgcheck=1, because dnf.Base()
builds a configuration of library defaults and never reads the file. A test built
on it would have been asserting the library's defaults back at itself.
Turning repo_gpgcheck on does not break the host. This is not an
afterthought: the crypto-policy role in this catalogue found that DEFAULT:OSPP,
a policy a Protection Profile asks for, stops dnf working entirely, and nothing
warns you at the moment you set it. So this role's live test cleans dnf's
metadata and reads the distribution's own repositories again with the policy in
force, and fails if they no longer verify. Rocky's metadata is signed;
makecache imports the release key and succeeds.
The unsigned repository the test refuses is a local one. createrepo_c over
a directory, a file:// baseurl, gpgcheck=0 on that repository so only
repo_gpgcheck can object - and dnf refuses it with "GPG verification is
enabled, but GPG signature is not available", naming the repomd.xml.asc it
could not find. No network, no third party, and the same refusal an attacker's
mirror would meet.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-aide
AIDE from AppStream on EL 10: a watched tree, a baseline database built once, and the oneshot unit and timer the package does not ship. The live test passes on an unchanged host, FAILS when a file appears inside a watched path and names it, ignores one inside an excluded path, and passes again once the change is gone. Original role, live-tested on Rocky Linux 10.
ansible-authelia
Authelia from the upstream release (sha256-verified) as a hardened system service on loopback with file users and sqlite; its secrets are generated once on the host and reach the service as AUTHELIA_*_FILE variables. The live test hashes a password with Authelia's hasher, logs in, sees a wrong password refused and an anonymous visitor sent to the portal. Original role, live-tested on Rocky 10.
ansible-bandit
bandit on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then scans a module that passes a string to subprocess.call with shell=True (B602, High, exit 1) and a clean module (exit 0). Pinned. Original role, live-tested on Rocky Linux 10.
ansible-boundary
boundary on EL 10 from releases.hashicorp.com; SHA256SUMS is signature-checked against HashiCorp's key before get_url trusts it, the live test re-checks both, then runs authenticate against a dead address ('connection refused') and database init with a throwaway config (parsed, root key loaded, then the database refused). Pinned. Original role, live-tested on Rocky Linux 10.
ansible-dockle
dockle on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then scans a one-layer image whose config names no user, expecting CIS-DI-0001 in the output, exit code 1 with --exit-level warn, and the warning counted in the JSON form. Pinned. Original role, live-tested on Rocky Linux 10.
ansible-gitleaks
gitleaks on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums file, and re-checked with sha256sum -c by the live test, which then plants a file holding an AWS access key that is not one and runs gitleaks detect over it, expecting 'leaks found: 1'. Original role, live-tested on Rocky Linux 10.