# RPM signing key is invalid on newer operating systems

**URL:** <https://discuss.elastic.co/t/rpm-signing-key-is-invalid-on-newer-operating-systems/327476>\
**Category:** Elasticsearch\
**Created:** [March 10, 2023, 9:43pm UTC](https://discuss.elastic.co/t/rpm-signing-key-is-invalid-on-newer-operating-systems/327476 "2023-03-10T21:43:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![twilson](https://avatars.discourse-cdn.com/v4/letter/t/2bfe46/32.png) [@twilson](https://discuss.elastic.co/u/twilson)\
**Post date:** [March 10, 2023, 9:43pm UTC](https://discuss.elastic.co/t/rpm-signing-key-is-invalid-on-newer-operating-systems/327476/1 "2023-03-10T21:43:41Z")

</div>

The signing key used for RPM packages (and I assume other package types) is no longer valid on newer operating systems since the key is SHA1 and these newer operating systems have deprecated SHA1.

Specifically, I'm trying to install elasticsearch 8.6.1 on a RHEL 9 system and get this when using your directions to import the signing key

```auto
rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch
warning: Signature not supported. Hash algorithm SHA1 not available.

```

There have been numerous topics opened regarding this issue in the forums, and none of them have ever received a public reply and have been closed due to age. I'd rather not have to bypass the gpg check in dnf, and I really don't want to enable SHA1 system-wide. Please create a new/additional key with SHA256/512 so the packages can again be managed with a package manager.

---

<div class="post-metadata">

**Author:** ![William\_Brafford](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/william_brafford/32/51559_2.png) [@William\_Brafford](https://discuss.elastic.co/u/William_Brafford)\
**Post date:** [March 20, 2023, 7:04pm UTC](https://discuss.elastic.co/t/rpm-signing-key-is-invalid-on-newer-operating-systems/327476/2 "2023-03-20T19:04:59Z")

</div>

I believe there is a Github issue for this: [rpm --import https://artifacts.elastic.co/GPG-KEY-elasticsearch not working on centOS stream. gives a key import error. · Issue #85876 · elastic/elasticsearch · GitHub](https://github.com/elastic/elasticsearch/issues/85876#issuecomment-1423361996)

We do intend to create a new signing key, but we don't know when it will happen. But when there is progress you will be more likely to see it on that github issue than here.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 17, 2023, 7:05pm UTC](https://discuss.elastic.co/t/rpm-signing-key-is-invalid-on-newer-operating-systems/327476/3 "2023-04-17T19:05:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
