[
https://issues.apache.org/jira/browse/VELOCITY-1002?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Claude Brisson closed VELOCITY-1002.
------------------------------------
Fix Version/s: 2.4.1
Assignee: Claude Brisson
Resolution: Fixed
Yes, release 2.4.1 was signed with the *wong* key, the key I used to sign
personal non-apache projects releases.
I added it to Velocity KEYS.
> KEYS file does not list the key that signed the 2.4.1 release
> -------------------------------------------------------------
>
> Key: VELOCITY-1002
> URL: https://issues.apache.org/jira/browse/VELOCITY-1002
> Project: Velocity
> Issue Type: Wish
> Reporter: Rafael Winterhalter
> Assignee: Claude Brisson
> Priority: Minor
> Fix For: 2.4.1
>
>
> The 2.4.1 release artifacts are signed with OpenPGP key
> 6F9D10E747DC79485ABB4F72B709E61252F136DD (Claude Brisson,
> <[email protected]>): the source and binary distributions under
> https://downloads.apache.org/velocity/engine/2.4.1/ and the Maven artifacts
> of org.apache.velocity:velocity-engine-core:2.4.1 on Central carry signatures
> by that key.
> https://downloads.apache.org/velocity/KEYS does not contain it. It lists two
> of the release manager's keys (AE4C69EC from 2009 and BEFEEF227A98B809 from
> 2016), and the key is not on
> https://people.apache.org/keys/committer/cbrisson.asc either. Anyone
> verifying the release as the ASF release documentation describes (import
> KEYS, then gpg --verify) gets "no public key" for 2.4.1.
> The signature itself verifies once the key is fetched from a keyserver, and
> the signer is the release manager, so this is the published KEYS file lagging
> the key in use rather than a problem with the release. Note that the key
> expired on 2025-09-10; the 2.4.1 signatures predate that (2024-10-14), but a
> future release will need a current key in KEYS as well.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]