Hi Thomas,

you seem to have cut the release, as it's signed by you. However I can't find you key (594ABF33ED102DF53F83CE43CFBB963ECC4F9C3A) on the MIT public key server.

Here is the message I receives when checking the key:


$ gpg --verify apache-sshd-2.17.1-src.tar.gz.asc apache-sshd-2.17.1-src.tar.gz
gpg: Signature made jeu. 22 janv. 2026 20:50:21 CET
gpg:                using EDDSA key 594ABF33ED102DF53F83CE43CFBB963ECC4F9C3A
gpg: Good signature from "Thomas Wolf <[email protected]>" [unknown]
gpg: WARNING: This key is not certified with a trusted signature!
gpg:          There is no indication that the signature belongs to the owner.
Primary key fingerprint: 2D06 E413 26CC 1A82 58B1  937C 081C A8E4 186A A7B6
     Subkey fingerprint: 594A BF33 ED10 2DF5 3F83  CE43 CFBB 963E CC4F 9C3A


In the mina root the KEYS file contains this:

gpg: key 081CA8E4186AA7B6: "Thomas Wolf <[email protected]>" not changed


I'm wondering if you have recently changed your key and forgot to update it in KEYS?

(FTR, I was able to verify the SHA512 signature)

Hello,

I've staged a candidate release for Apache Mina SSHD 2.17.1.

Sorry that I have to bother you again. Due to a tooling bug that I
hadn't noticed the Maven release of 2.17.0 was broken: the root pom
was not published.

This is fixed with this patch release. For details of the problem,
see https://github.com/apache/mina-sshd/issues/875

Thanks to Gary for finding the root cause!

Official staging repo:
  https://dist.apache.org/repos/dist/dev/mina/sshd/2.17.1/
Maven staging repo:
https://repository.apache.org/content/repositories/orgapachemina-1130


Git tag:
  https://github.com/apache/mina-sshd/commits/sshd-2.17.1
Change notes:

https://github.com/apache/mina-sshd/blob/sshd-2.17.1/docs/changes/2.17.1.md


Apache MINA KEYS file:
  https://downloads.apache.org/mina/KEYS

The SHA512 checksum files have been created with 'shasum -a512 -b'.

Please review and vote!

Cheers,

  Thomas

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to