chef-datadog icon indicating copy to clipboard operation
chef-datadog copied to clipboard

2022 Linux Agent Key Rotation for someone using v4.10.0

Open vpilania opened this issue 3 years ago • 3 comments

Hi Team,

I'm using v4.10.0 for Datadog Linux agent that I'm installing on Amazon Linux machines (both 1 & 2). I referred to this page which mentions I should be using v4.11.0+ in order to prevent any issues after April'22 as GPG keys will be rotated.

However after following the process to check whether I'm affected or not I'm getting successful response to this command - $ rpm -qa | grep gpg-pubkey-fd4bf915

Does that mean I dont need to move to v4.11.0+ and is the notification about that is correct as on v4.10.0 to it's working fine?

P.S. - Datadog linux agent version is 7.34.0 on my AWS machines.

vpilania avatar Mar 29 '22 16:03 vpilania

Hi @vpilania,

Indeed, as you found, for RPM-based systems v4.10 already did trust the new signing keys, so you don't need to do any further action. The reason we mention 4.11+ in the docs is that this is the version where we introduced the changes DEB-based systems.

So, if if you are not running Debian, Ubuntu, or any Debian-based distro, 4.10 already works for you. If you have any Debian-based Linuxes running, you will need to update to 4.11+.

Albert

albertvaka avatar Mar 29 '22 17:03 albertvaka

Thanks @albertvaka . I think you shud improve this help guide then to avoid any confusion to anyone like me. It should clearly mention what you're saying above.

vpilania avatar Mar 30 '22 11:03 vpilania

Thanks for the feedback @vpilania! 😄 We discussed this and to keep the docs as simple as possible, we prefer to only list one version there.

albertvaka avatar Mar 30 '22 19:03 albertvaka