Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

GPG key used to sign debian repository changed #209

Closed
stbuehler opened this issue Jan 18, 2020 · 2 comments
Closed

GPG key used to sign debian repository changed #209

stbuehler opened this issue Jan 18, 2020 · 2 comments

Comments

@stbuehler
Copy link

A key rollover should be documented, and I can't find any note regarding it. Also please don't create a new key every month:

Old key:

pub   rsa4096 2019-11-22 [SCEA] [expires: 2024-11-20]
      CC160DF5CEF1B148857EBA29F9CC653EBE9CF76D
uid           Amazon Services LLC (Amazon Corretto release) <corretto-team@amazon.com>

New key (downloaded from https://apt.corretto.aws/corretto.key):

pub   rsa4096 2019-12-05 [SCEA] [expires: 2024-12-03]
      6DC3636DAE534049C8B94623A122542AB04F24E3
uid           Amazon Services LLC (Amazon Corretto release) <corretto-team@amazon.com>

I'm pretty sure I observed the old key "Dec 21" (not quite sure how long apt has been complaining).

@cliveverghese
Copy link
Contributor

hi @stbuehler

Both the keys are owned by us and safe to use. The key currently in place is what we will keep signing future releases with (i.e. 6DC3636DAE534049C8B94623A122542AB04F24E3) although we previously released our apt-repos signed with our pre-release key (i.e. key id: CC160DF5CEF1B148857EBA29F9CC653EBE9CF76D ). We will update our change log to make this clear. Thanks for pointing it out.

@stbuehler
Copy link
Author

Thanks for the clarification!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants