Rafael Winterhalter created VELOCITY-1002:
---------------------------------------------
Summary: KEYS file does not list the key that signed the 2.4.1
release
Key: VELOCITY-1002
URL: https://issues.apache.org/jira/browse/VELOCITY-1002
Project: Velocity
Issue Type: Wish
Reporter: Rafael Winterhalter
The 2.4.1 release artifacts are signed with OpenPGP key
6F9D10E747DC79485ABB4F72B709E61252F136DD (Claude Brisson,
<[email protected]>): the source and binary distributions under
https://downloads.apache.org/velocity/engine/2.4.1/ and the Maven artifacts of
org.apache.velocity:velocity-engine-core:2.4.1 on Central carry signatures by
that key.
https://downloads.apache.org/velocity/KEYS does not contain it. It lists two of
the release manager's keys (AE4C69EC from 2009 and BEFEEF227A98B809 from 2016),
and the key is not on https://people.apache.org/keys/committer/cbrisson.asc
either. Anyone verifying the release as the ASF release documentation describes
(import KEYS, then gpg --verify) gets "no public key" for 2.4.1.
The signature itself verifies once the key is fetched from a keyserver, and the
signer is the release manager, so this is the published KEYS file lagging the
key in use rather than a problem with the release. Note that the key expired on
2025-09-10; the 2.4.1 signatures predate that (2024-10-14), but a future
release will need a current key in KEYS as well.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]