The dnf Signature Check That Is Off By Default

dnf checks the signature on a package it downloads and not on one you hand it: localpkg_gpgcheck is absent from dnf.conf and defaults to off, and so is repo_gpgcheck. This role sets both and proves each by what it prevents, refusing an unsigned package and an unsigned repository it builds, then checking the distribution's repositories still verify. Original role, live-tested on Rocky Linux 10.

ansibleSecurity & Secrets

Verification

Live-tested

Really deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.

Conformance

  • Static validation (yamllint · ansible-lint)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-09-27 · podman 4.9.3 · ansible 2.21.4 · how we verify

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: live-tested](https://www.iac-bazaar.com/api/artifacts/ansible-dnf-security/badge)](https://www.iac-bazaar.com/catalog/ansible-dnf-security?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Ansible role 1.0.0, live-tested on IaC Bazaar: [The dnf Signature Check That Is Off By Default](https://www.iac-bazaar.com/catalog/ansible-dnf-security?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```yaml
# The dnf Signature Check That Is Off By Default: https://www.iac-bazaar.com/catalog/ansible-dnf-security (download from your IaC Bazaar account)
```

Preview:IaC Bazaar: live-tested

Documentation

dnf-security

dnf checks the signature on a package it downloads, and not on one you hand it. gpgcheck=1 is in the shipped configuration; localpkg_gpgcheck is not in it at all and defaults to off, so dnf install ./something.rpm installs an unsigned package without a word. repo_gpgcheck is missing the same way, which leaves a repository's metadata unverified. This role sets all three and proves each by the thing it is supposed to prevent.

No download, and no version to pin. dnf is the distribution. What the role owns is four lines in /etc/dnf/dnf.conf - dnf 4, which is what EL 10 carries, has no drop-in directory for them - and the proof that the host now refuses what it used to accept.

A repository file can opt itself out, and that beats dnf.conf. Measured both ways: a repository asking for repo_gpgcheck=1 was honoured against a [main] that said 0, and a repository setting gpgcheck=0 keeps its own answer. The role does not rewrite anybody else's repository file - it names the ones that opt out and stops, which is dnf_security_fail_on_unchecked_repos.

rpm -K exits 0 on a completely unsigned package. On the fixture this role's test builds, rpm -Kv lists four digests, no signature, and returns success; rpm -qpi says Signature : (none). Anything that treats rpm -K as a signature check is reading a digest as a provenance claim, which is why the live test asserts the fixture is unsigned through the signature header before it draws any conclusion from dnf's refusal.

dnf config-manager --dump is dnf's sshd -T. It prints the configuration dnf will use, defaults included, which is what the test reads. The obvious alternative does not work: python3 -c "import dnf; dnf.Base().conf.localpkg_gpgcheck" answered False for all three booleans against a dnf.conf that said 1, and answered gpgcheck=False against a shipped gpgcheck=1, because dnf.Base() builds a configuration of library defaults and never reads the file. A test built on it would have been asserting the library's defaults back at itself.

Turning repo_gpgcheck on does not break the host. This is not an afterthought: the crypto-policy role in this catalogue found that DEFAULT:OSPP, a policy a Protection Profile asks for, stops dnf working entirely, and nothing warns you at the moment you set it. So this role's live test cleans dnf's metadata and reads the distribution's own repositories again with the policy in force, and fails if they no longer verify. Rocky's metadata is signed; makecache imports the release key and succeeds.

The unsigned repository the test refuses is a local one. createrepo_c over a directory, a file:// baseurl, gpgcheck=0 on that repository so only repo_gpgcheck can object - and dnf refuses it with "GPG verification is enabled, but GPG signature is not available", naming the repomd.xml.asc it could not find. No network, no third party, and the same refusal an attacker's mirror would meet.

License

Commercial - IaC Bazaar EULA. (c) IaC Bazaar.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Variables
  • Test

Related modules

Live-tested

ansible-aide

AIDE from AppStream on EL 10: a watched tree, a baseline database built once, and the oneshot unit and timer the package does not ship. The live test passes on an unchanged host, FAILS when a file appears inside a watched path and names it, ignores one inside an excluded path, and passes again once the change is gone. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-authelia

Authelia from the upstream release (sha256-verified) as a hardened system service on loopback with file users and sqlite; its secrets are generated once on the host and reach the service as AUTHELIA_*_FILE variables. The live test hashes a password with Authelia's hasher, logs in, sees a wrong password refused and an anonymous visitor sent to the portal. Original role, live-tested on Rocky 10.

View module
Live-tested

ansible-bandit

bandit on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then scans a module that passes a string to subprocess.call with shell=True (B602, High, exit 1) and a clean module (exit 0). Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-boundary

boundary on EL 10 from releases.hashicorp.com; SHA256SUMS is signature-checked against HashiCorp's key before get_url trusts it, the live test re-checks both, then runs authenticate against a dead address ('connection refused') and database init with a throwaway config (parsed, root key loaded, then the database refused). Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-dockle

dockle on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then scans a one-layer image whose config names no user, expecting CIS-DI-0001 in the output, exit code 1 with --exit-level warn, and the warning counted in the JSON form. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-gitleaks

gitleaks on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums file, and re-checked with sha256sum -c by the live test, which then plants a file holding an AWS access key that is not one and runs gitleaks detect over it, expecting 'leaks found: 1'. Original role, live-tested on Rocky Linux 10.

View module