# Local EPEL repo sync

**URL:** <https://forums.rockylinux.org/t/local-epel-repo-sync/9020>\
**Category:** Rocky Linux Help & Support\
**Created:** [February 25, 2023, 2:53pm UTC](https://forums.rockylinux.org/t/local-epel-repo-sync/9020 "2023-02-25T14:53:44Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![dsexton18](https://avatars.discourse-cdn.com/v4/letter/d/85f322/32.png) [@dsexton18](https://forums.rockylinux.org/u/dsexton18)\
**Post date:** [February 25, 2023, 2:53pm UTC](https://forums.rockylinux.org/t/local-epel-repo-sync/9020/1 "2023-02-25T14:53:45Z")

</div>

I have tried to dnf reposync for EPAL all the rpms are downloaded but then it removes them due to GPG signature check failed. How do I fix that?

dnf reposync -g --delete -p /data/repos/ --repoid=epel --newest-only --download-metadata

---

<div class="post-metadata">

**Author:** ![label](https://avatars.discourse-cdn.com/v4/letter/l/c5a1d2/32.png) [@label](https://forums.rockylinux.org/u/label)\
**Post date:** [February 25, 2023, 4:32pm UTC](https://forums.rockylinux.org/t/local-epel-repo-sync/9020/2 "2023-02-25T16:32:20Z")

</div>

You need their gpg key imported into your rpm database first. I would install epel-release and then it’ll drop a gpg key for you.

---

<div class="post-metadata">

**Author:** ![limbooface](https://avatars.discourse-cdn.com/v4/letter/l/4af34b/32.png) [@limbooface](https://forums.rockylinux.org/u/limbooface)\
**Post date:** [February 25, 2023, 10:10pm UTC](https://forums.rockylinux.org/t/local-epel-repo-sync/9020/3 "2023-02-25T22:10:43Z")

</div>

If you download the repo file to your system you can remove the gpg check in the repo file by setting the value to 0. This is if you have built a local repository.

---

<div class="post-metadata">

**Author:** ![jlehtone](https://avatars.discourse-cdn.com/v4/letter/j/e9a140/32.png) [@jlehtone](https://forums.rockylinux.org/u/jlehtone)\
**Post date:** [February 25, 2023, 10:50pm UTC](https://forums.rockylinux.org/t/local-epel-repo-sync/9020/4 "2023-02-25T22:50:12Z")

</div>

> [@limbooface](#):
>
> This is if you have built a local repository.

… of unsigned packages that you do trust.

Here, however, we are talking about a mirror of EPEL. EPEL packages are signed and EPEL key is available. There is no reason to disable that integrity check.

---

<div class="post-metadata">

**Author:** ![limbooface](https://avatars.discourse-cdn.com/v4/letter/l/4af34b/32.png) [@limbooface](https://forums.rockylinux.org/u/limbooface)\
**Post date:** [February 25, 2023, 10:52pm UTC](https://forums.rockylinux.org/t/local-epel-repo-sync/9020/5 "2023-02-25T22:52:49Z")

</div>

I had the gpg key added to my repo and it still deleted the packages so that is why I removed the check.

---

<div class="post-metadata">

**Author:** ![dsexton18](https://avatars.discourse-cdn.com/v4/letter/d/85f322/32.png) [@dsexton18](https://forums.rockylinux.org/u/dsexton18)\
**Post date:** [February 26, 2023, 2:18pm UTC](https://forums.rockylinux.org/t/local-epel-repo-sync/9020/6 "2023-02-26T14:18:11Z")

</div>

I installed the epel-release like below still same results as before. For now I disabled pgp check.

dnf install epel-release  
dnf update

[epel]  
name=Extra Packages for Enterprise Linux 8 - $basearch

# It is much more secure to use the metalink, but if you wish to use a local mir ror

# place its address here.

#baseurl=[https://download.example/pub/epel/8/Everything/$basearch](https://download.example/pub/epel/8/Everything/$basearch)  
metalink=[https://mirrors.fedoraproject.org/metalink?repo=epel-8&arch=$basearch&i](https://mirrors.fedoraproject.org/metalink?repo=epel-8&arch=$basearch&i) nfra=$infra&content=$contentdir  
enabled=1  
gpgcheck=0  
countme=1  
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-EPEL-8

[epel-debuginfo]  
name=Extra Packages for Enterprise Linux 8 - $basearch - Debug

# It is much more secure to use the metalink, but if you wish to use a local mir ror

# place its address here.

#baseurl=[https://download.example/pub/epel/8/Everything/$basearch/debug](https://download.example/pub/epel/8/Everything/$basearch/debug)  
metalink=[https://mirrors.fedoraproject.org/metalink?repo=epel-debug-8&arch=$base](https://mirrors.fedoraproject.org/metalink?repo=epel-debug-8&arch=$base) arch&infra=$infra&content=$contentdir  
enabled=0  
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-EPEL-8  
gpgcheck=0

[epel-source]  
name=Extra Packages for Enterprise Linux 8 - $basearch - Source

# It is much more secure to use the metalink, but if you wish to use a local mir ror

# place it’s address here.

#baseurl=[https://download.example/pub/epel/8/Everything/source/tree/](https://download.example/pub/epel/8/Everything/source/tree/)  
metalink=[https://mirrors.fedoraproject.org/metalink?repo=epel-source-8&arch=$bas](https://mirrors.fedoraproject.org/metalink?repo=epel-source-8&arch=$bas) earch&infra=$infra&content=$contentdir  
enabled=0  
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-EPEL-8  
gpgcheck=0

---

<div class="post-metadata">

**Author:** ![Ritov](https://avatars.discourse-cdn.com/v4/letter/r/3ec8ea/32.png) [@Ritov](https://forums.rockylinux.org/u/Ritov)\
**Post date:** [February 26, 2023, 11:37pm UTC](https://forums.rockylinux.org/t/local-epel-repo-sync/9020/7 "2023-02-26T23:37:28Z")

</div>

You should add

> [@dsexton18](#):
>
> gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-EPEL-8

to your local repo/dnf config. Otherwise the check doesn’t know what to use.

May I ask why you do a local repo of EPEL?

---

<div class="post-metadata">

**Author:** ![brian](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/brian/32/5777_2.png) [@brian](https://forums.rockylinux.org/u/brian)\
**Post date:** [August 25, 2023, 3:23am UTC](https://forums.rockylinux.org/t/local-epel-repo-sync/9020/8 "2023-08-25T03:23:32Z")

</div>


