meant to send this to a maven list... but any info great~

thanks
david jencks

On Nov 28, 2009, at 2:45 PM, David Jencks wrote:

Apache has recently requested that all apache releases be signed with 4096 bit keys and SHA512, see http://www.apache.org/dev/openpgp.html

I've released some artifacts using maven signed with an older 1024 bit key and most likely SHA1.

Is there any maven support for re-signing these older artifacts with a new longer key? If not, does anyone have any advice for a non- maven way to do it?

thanks
david jencks


Reply via email to