bug-gnulib
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: announce-gen and OpenPGP key servers


From: Simon Josefsson
Subject: Re: announce-gen and OpenPGP key servers
Date: Mon, 02 Aug 2021 12:09:06 +0200
User-agent: Evolution 3.38.3-1

sön 2021-08-01 klockan 17:47 +0200 skrev Bernhard Voelker:
> On 7/27/21 11:38 AM, Simon Josefsson via Gnulib discussion list
> wrote:
> > Let's discuss and see what we can do.
> Isn't this what the "release GPG keys" on Savannah are for?
> 
> Each project maintainer can set them up correctly under "Edit public
> info":
>   "
> https://savannah.gnu.org/project/admin/editgroupinfo.php?group=${PROJECT}
> "
> 
> The result can be downloaded by users for verification:
>   "
> https://savannah.gnu.org/project/release-gpgkeys.php?group=${PROJECT}&download=1
> "
> e.g. coreutils':
>   "
> https://savannah.gnu.org/project/release-gpgkeys.php?group=coreutils&download=1
> "
> 
> Downstream sometimes use them, e.g. SUSE and openSUSE are verifying
> the keys on their Open Build Service.

Right, thanks for pointing that out.  It can be used in some
situations.  One concern is that the set of keys trusted for uploads to
ftp.gnu.org is a a different set of keys, and not all GNU projects use
Savannah.

/Simon





reply via email to

[Prev in Thread] Current Thread [Next in Thread]