On Tue, 6 Oct 2026 at 17:50, Branko Čibej <[email protected]> wrote: > On 6. 10. 2026 16:38, Ivan Zhakov wrote: > > On Tue, 6 Oct 2026 at 13:42, Branko Čibej <[email protected]> wrote: > >> On 6. 10. 2026 10:57, Ivan Zhakov wrote: >> >> On Mon, 5 Oct 2026 at 19:42, Branko Čibej <[email protected]> wrote: >> >>> On 24. 9. 2026 13:21, Evgeny Kotkov via dev wrote: >>> >>> The 1.15.0 release artifacts are now available for testing/signing. >>> Please get the tarballs from >>> https://dist.apache.org/repos/dist/dev/subversion >>> and add your signatures there. >>> >>> Note: 1.15.0 tarballs should be functionally identical to 1.15.0-rc4 (they >>> are built from the same revision r1937767), with the only difference being >>> in the version number. >>> >>> Thanks! >>> >>> >>> I have an issue with the signatures for the .zip file: >>> >>> gpg: assuming signed data in 'dev/subversion-1.15.0.zip' >>> ... skipped sig from Evgeny >>> gpg: Signature made Fri Sep 25 12:54:09 2026 CEST >>> gpg: using RSA key D6678482E2ED5750E28B69292FB22D0D4ADC662A >>> gpg: key 2FB22D0D4ADC662A: new key but contains no user ID - skipped >>> gpg: Can't check signature: No public key >>> >>> >>> I have the key in my keyring, but a public key without a user ID isn't >>> valid. Could whoever owns this key add an ID and upload the updated key, >>> please? Ivan, I think that's your new key, given what I see in the logs? >>> >>> It's my key. >> >> It's the same key that I used to sign Subversion 1.15.0-rc4. >> >> It's available on people.apache.org: >> https://people.apache.org/keys/committer/ivan >> >> And PGP keyservers: >> >> https://keyserver.ubuntu.com/pks/lookup?search=D667+8482+E2ED+5750+E28B++6929+2FB2+2D0D+4ADC+662A&fingerprint=on&op=index >> >> https://keys.openpgp.org/vks/v1/by-fingerprint/D6678482E2ED5750E28B69292FB22D0D4ADC662A >> >> I also see it in the subversion-1.15.0.KEYS file. >> [[[ >> ASF ID: ivan >> LDAP PGP key: D667 8482 E2ED 5750 E28B 6929 2FB2 2D0D 4ADC 662A >> >> pub rsa4096/2FB22D0D4ADC662A 2026-07-14 [SC] >> Key fingerprint = D667 8482 E2ED 5750 E28B 6929 2FB2 2D0D 4ADC 662A >> uid [ unknown] Ivan Zhakov (CODE SIGNING KEY) < >> [email protected]> >> sub rsa4096/C62470648595D168 2026-07-14 [E] >> Key fingerprint = 9F3F 4DF5 6E1A EF95 73AB F318 C624 7064 8595 D168 >> .... >> ]]] >> >> May be I am missing something? >> >> >> Or maybe I am. I didn't see this key in my rc4 tests, because I did the >> signature check before you signed. Could it be gpg somehow got an >> incomplete copy of it? That would be a huge bug, but I guess it's possible. >> Let me check ... >> >> >> ... so it turns out that your key did not propagate correctly to >> keys.openpgp.org which I use by default, this is what I get: >> >> $ gpg --keyserver hkps://keys.openpgp.org --recv-keys 2FB22D0D4ADC662A >> gpg: key 2FB22D0D4ADC662A: new key but contains no user ID - skipped >> gpg: Total number processed: 1 >> gpg: w/o user IDs: 1 >> >> >> Well, it's strange because the key is on keys.openpgp.org: > > https://keys.openpgp.org/vks/v1/by-fingerprint/D6678482E2ED5750E28B69292FB22D0D4ADC662A > > > > Yes, the key file is there, but it's incomplete. I downloaded it and > checked the contents and there's no UID. > > $ gpg -v D6678482E2ED5750E28B69292FB22D0D4ADC662A.asc > gpg: enabled compatibility flags: > gpg: WARNING: no command supplied. Trying to guess what you mean ... > gpg: armor header: Comment: D667 8482 E2ED 5750 E28B 6929 2FB2 2D0D 4ADC 662A > pub rsa4096 2026-07-14 [SCEA] > D6678482E2ED5750E28B69292FB22D0D4ADC662A > sub rsa4096 2026-07-14 [E] > sig 2FB22D0D4ADC662A 2026-07-14 [keybind] > > > Only the pub, sub and sig fields are there, the uid field is missing. That > field is present in the key that's available on keyserver.ubuntu.com. > > It turns out that keys.openpgp.org server doesn't publish UID key information without explicit confirmation via email. I have manually uploaded key via website and confirmed my email.
Now keys.openpgp.org has UID information: [[[ $ gpg -v D6678482E2ED5750E28B69292FB22D0D4ADC662A.asc gpg: enabled compatibility flags: gpg: WARNING: no command supplied. Trying to guess what you mean ... gpg: armor header: Comment: D667 8482 E2ED 5750 E28B 6929 2FB2 2D0D 4ADC 662A gpg: armor header: Comment: Ivan Zhakov (CODE SIGNING KEY) <[email protected]> pub rsa4096 2026-07-14 [SC] D6678482E2ED5750E28B69292FB22D0D4ADC662A uid Ivan Zhakov (CODE SIGNING KEY) <[email protected]> sig 2FB22D0D4ADC662A 2026-07-14 [selfsig] sub rsa4096 2026-07-14 [E] sig 2FB22D0D4ADC662A 2026-07-14 [keybind] ]]] -- Ivan Zhakov

