Check
Confirm Oracle package-signing key is installed on the system and verify its fingerprint matches vendor value.
Note: The GPG key is defined in key file "/etc/pki/rpm-gpg/RPM-GPG-KEY-oracle" by default.
List Oracle GPG keys installed on the system:
$ sudo rpm -q --queryformat "%{SUMMARY}\n" gpg-pubkey | grep -i "oracle"
gpg(Oracle OSS group (Open Source Software group) <
[email protected]>)
If Oracle GPG key is not installed, this is a finding.
List key fingerprint of installed Oracle GPG key:
$ sudo gpg -q --keyid-format short --with-fingerprint /etc/pki/rpm-gpg/RPM-GPG-KEY-oracle
If key file "/etc/pki/rpm-gpg/RPM-GPG-KEY-oracle" is missing, this is a finding.
Example output:
pub rsa4096/AD986DA3 2019-04-09 [SC] [expires: 2039-04-04]
Key fingerprint = 76FD 3DB1 3AB6 7410 B89D B10E 8256 2EA9 AD98 6DA3
uid Oracle OSS group (Open Source Software group) <
[email protected]>
sub rsa4096/D95DC12B 2019-04-09 [E] [expires: 2039-04-04]
Compare key fingerprint of installed Oracle GPG key with fingerprint listed for OL 8 on Oracle verification webpage at https://linux.oracle.com/security/gpg/#gpg.
If key fingerprint does not match, this is a finding.