tsem.nl

RPM Repository
Enterprise Linux 10 / x86_64

Signed packages.
Simple setup.

tsem.nl publishes binary RPMs, source RPMs, SBOMs, and signed repository metadata. Use the standard setup below, or verify the publisher first when your policy requires an independent bootstrap.

tsem.nl
Standard setup

Add the repository

curl --fail --location --proto '=https' \
  --output bluesmoke-release.noarch.rpm \
  https://repo.tsem.nl/bluesmoke-release-latest.noarch.rpm
sudo dnf install ./bluesmoke-release.noarch.rpm

This standard path trusts HTTPS for the initial download. After setup, DNF verifies packages and repository metadata with the installed signing key.

After setup

Verification stays on

The release package installs the repository definition and public key. Package and repository-metadata verification remain enabled for future installs and updates.

Packages
gpgcheck=1
Metadata
repo_gpgcheck=1
Transport
sslverify=1
Verify the publisher before installing

For an independently authenticated bootstrap, obtain the complete fingerprint through a channel you already trust. Download the key, compare all 40 hexadecimal characters, then import it and verify the release RPM before installation.

D971 CC9D 54F2 1B0C 6BC8 1E34 4479 527D FC68 CF50
curl --fail --location --proto '=https' \
  --output RPM-GPG-KEY-BlueSmoke \
  https://repo.tsem.nl/keys/RPM-GPG-KEY-BlueSmoke
gpg --batch --show-keys --with-fingerprint \
  RPM-GPG-KEY-BlueSmoke
sudo rpmkeys --import RPM-GPG-KEY-BlueSmoke
curl --fail --location --proto '=https' \
  --output bluesmoke-release.noarch.rpm \
  https://repo.tsem.nl/bluesmoke-release-latest.noarch.rpm
rpmkeys --checksig --verbose bluesmoke-release.noarch.rpm
sudo dnf install ./bluesmoke-release.noarch.rpm

Stop if the fingerprint or RPM signature does not match.

Manual configuration and troubleshooting

Use this path for configuration management or recovery after verifying and importing the signing key above.

sudo install -m 0644 RPM-GPG-KEY-BlueSmoke \
  /etc/pki/rpm-gpg/RPM-GPG-KEY-BlueSmoke
sudo tee /etc/yum.repos.d/bluesmoke.repo >/dev/null <<'EOF'
[bluesmoke]
name=BlueSmoke RPM Repository for Enterprise Linux 10 - $basearch
baseurl=https://repo.tsem.nl/el/10/$basearch/
enabled=1
gpgcheck=1
repo_gpgcheck=1
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-BlueSmoke
sslverify=1
EOF
sudo dnf makecache --refresh \
  --disablerepo='*' --enablerepo=bluesmoke
Browse

Repository contents

NameLast modifiedSize

el/2026-07-24 13:53 -