Hi, > gpg_check: > gpg: Signature made Wed Nov 11 09:19:23 2015 IST using RSA key ID DA9CCFF2 > gpg: Good signature from "Alex Harui (CODE SIGNING KEY) <aha...@apache.org>" > gpg: WARNING: This key is not certified with a trusted signature! > gpg: There is no indication that the signature belongs to the owner. > Primary key fingerprint: E7F7 B7D4 944C AC45 7A14 C0E9 83E0 431C DA9C CFF2 > gpg: Signature made Wed Nov 11 09:19:23 2015 IST using RSA key ID DA9CCFF2 > gpg: Good signature from "Alex Harui (CODE SIGNING KEY) <aha...@apache.org>" > gpg: WARNING: This key is not certified with a trusted signature! > gpg: There is no indication that the signature belongs to the owner. > Primary key fingerprint: E7F7 B7D4 944C AC45 7A14 C0E9 83E0 431C DA9C CFF2
That’s fine just means Alex is not in your web of trust. Thanks, Justin