[ 
https://issues.apache.org/jira/browse/MNGSITE-485?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17552451#comment-17552451
 ] 

Baiyang Li commented on MNGSITE-485:
------------------------------------

Hey Osipov,

Sorry for the delay, I still meet an issue when I run above steps. The error is 
shown as below.
{code:java}
gpg: Good signature from "Michael Osipov (Java developer) <[email protected]>" 
[unknown]
gpg:                 aka "Michael Osipov <[email protected]>" [unknown]
gpg: WARNING: This key is not certified with a trusted signature!
gpg:          There is no indication that the signature belongs to the 
owner.{code}
May I know do you meet this error on your side as well? 

Thanks.

> Expired signature in provided KEYS file on the download page
> ------------------------------------------------------------
>
>                 Key: MNGSITE-485
>                 URL: https://issues.apache.org/jira/browse/MNGSITE-485
>             Project: Maven Project Web Site
>          Issue Type: Bug
>            Reporter: Baiyang Li
>            Assignee: Michael Osipov
>            Priority: Major
>
> Hey,
> I met the same expired signature issue described in this close 
> [issue|https://issues.apache.org/jira/browse/MNGSITE-458?page=com.atlassian.jira.plugin.system.issuetabpanels%3Acomment-tabpanel&focusedCommentId=17410236#comment-17410236].
> When i follow the procedure to verify the signature using the KEYS file, both 
> provided on the maven's download page::
>  * KEYS file import: gpg --import KEYS
>  * signature verification; gpg --verify .\apache-maven-3.8.2-bin.tar.gz.asc 
> .\apache-maven-3.8.2-bin.tar.gz
> I've got the following message at the second step:
> gpg: Good signature from "Michael Osipov (Java developer) 
> <[email protected]>" [expired]
> gpg:                 aka "Michael Osipov <[email protected]>" [expired]
> gpg: Note: This key has expired!
> According to the same procedure: "A signature is valid, if gpg verifies the 
> .asc as a good signature, and doesn't complain about expired or revoked 
> keys", so, technically, the signature is not valid.



--
This message was sent by Atlassian Jira
(v8.20.7#820007)

Reply via email to