On Tue, 6 Oct 2026 at 17:50, Branko Čibej <[email protected]> wrote:

> On 6. 10. 2026 16:38, Ivan Zhakov wrote:
>
> On Tue, 6 Oct 2026 at 13:42, Branko Čibej <[email protected]> wrote:
>
>> On 6. 10. 2026 10:57, Ivan Zhakov wrote:
>>
>> On Mon, 5 Oct 2026 at 19:42, Branko Čibej <[email protected]> wrote:
>>
>>> On 24. 9. 2026 13:21, Evgeny Kotkov via dev wrote:
>>>
>>> The 1.15.0 release artifacts are now available for testing/signing.
>>> Please get the tarballs from
>>>   https://dist.apache.org/repos/dist/dev/subversion
>>> and add your signatures there.
>>>
>>> Note: 1.15.0 tarballs should be functionally identical to 1.15.0-rc4 (they
>>> are built from the same revision r1937767), with the only difference being
>>> in the version number.
>>>
>>> Thanks!
>>>
>>>
>>> I have an issue with the signatures for the .zip file:
>>>
>>> gpg: assuming signed data in 'dev/subversion-1.15.0.zip'
>>> ... skipped sig from Evgeny
>>> gpg: Signature made Fri Sep 25 12:54:09 2026 CEST
>>> gpg:                using RSA key D6678482E2ED5750E28B69292FB22D0D4ADC662A
>>> gpg: key 2FB22D0D4ADC662A: new key but contains no user ID - skipped
>>> gpg: Can't check signature: No public key
>>>
>>>
>>> I have the key in my keyring, but a public key without a user ID isn't
>>> valid. Could whoever owns this key add an ID and upload the updated key,
>>> please? Ivan, I think that's your new key, given what I see in the logs?
>>>
>>> It's my key.
>>
>> It's the same key that I used to sign Subversion 1.15.0-rc4.
>>
>> It's available on people.apache.org:
>> https://people.apache.org/keys/committer/ivan
>>
>> And PGP keyservers:
>>
>> https://keyserver.ubuntu.com/pks/lookup?search=D667+8482+E2ED+5750+E28B++6929+2FB2+2D0D+4ADC+662A&fingerprint=on&op=index
>>
>> https://keys.openpgp.org/vks/v1/by-fingerprint/D6678482E2ED5750E28B69292FB22D0D4ADC662A
>>
>> I also see it in the subversion-1.15.0.KEYS file.
>> [[[
>> ASF ID: ivan
>> LDAP PGP key: D667 8482 E2ED 5750 E28B  6929 2FB2 2D0D 4ADC 662A
>>
>> pub   rsa4096/2FB22D0D4ADC662A 2026-07-14 [SC]
>>       Key fingerprint = D667 8482 E2ED 5750 E28B  6929 2FB2 2D0D 4ADC 662A
>> uid                 [ unknown] Ivan Zhakov (CODE SIGNING KEY) <
>> [email protected]>
>> sub   rsa4096/C62470648595D168 2026-07-14 [E]
>>       Key fingerprint = 9F3F 4DF5 6E1A EF95 73AB  F318 C624 7064 8595 D168
>> ....
>> ]]]
>>
>> May be I am missing something?
>>
>>
>> Or maybe I am. I didn't see this key in my rc4 tests, because I did the
>> signature check before you signed. Could it be gpg somehow got an
>> incomplete copy of it? That would be a huge bug, but I guess it's possible.
>> Let me check ...
>>
>>
>> ... so it turns out that your key did not propagate correctly to
>> keys.openpgp.org which I use by default, this is what I get:
>>
>> $ gpg --keyserver hkps://keys.openpgp.org --recv-keys 2FB22D0D4ADC662A
>> gpg: key 2FB22D0D4ADC662A: new key but contains no user ID - skipped
>> gpg: Total number processed: 1
>> gpg:           w/o user IDs: 1
>>
>>
>> Well, it's strange because the key is on keys.openpgp.org:
>
> https://keys.openpgp.org/vks/v1/by-fingerprint/D6678482E2ED5750E28B69292FB22D0D4ADC662A
>
>
>
> Yes, the key file is there, but it's incomplete. I downloaded it and
> checked the contents and there's no UID.
>
> $ gpg -v D6678482E2ED5750E28B69292FB22D0D4ADC662A.asc
> gpg: enabled compatibility flags:
> gpg: WARNING: no command supplied.  Trying to guess what you mean ...
> gpg: armor header: Comment: D667 8482 E2ED 5750 E28B  6929 2FB2 2D0D 4ADC 662A
> pub   rsa4096 2026-07-14 [SCEA]
>       D6678482E2ED5750E28B69292FB22D0D4ADC662A
> sub   rsa4096 2026-07-14 [E]
> sig        2FB22D0D4ADC662A 2026-07-14   [keybind]
>
>
> Only the pub, sub and sig fields are there, the uid field is missing. That
> field is present in the key that's available on keyserver.ubuntu.com.
>
>
It turns out that keys.openpgp.org server doesn't publish UID key
information without explicit confirmation via email. I have manually
uploaded key via website and confirmed my email.

Now keys.openpgp.org has UID information:
[[[
$ gpg -v D6678482E2ED5750E28B69292FB22D0D4ADC662A.asc
gpg: enabled compatibility flags:
gpg: WARNING: no command supplied.  Trying to guess what you mean ...
gpg: armor header: Comment: D667 8482 E2ED 5750 E28B  6929 2FB2 2D0D 4ADC
662A
gpg: armor header: Comment: Ivan Zhakov (CODE SIGNING KEY) <[email protected]>
pub   rsa4096 2026-07-14 [SC]
      D6678482E2ED5750E28B69292FB22D0D4ADC662A
uid           Ivan Zhakov (CODE SIGNING KEY) <[email protected]>
sig        2FB22D0D4ADC662A 2026-07-14   [selfsig]
sub   rsa4096 2026-07-14 [E]
sig        2FB22D0D4ADC662A 2026-07-14   [keybind]
]]]

-- 
Ivan Zhakov

Reply via email to