#1554 closed task (fixed)

sign release tarballs using gpg

Reported by: davidsarah Owned by: warner
Priority: major Milestone: 1.9.1
Component: packaging Version: 1.9.0a2
Keywords: security Cc:
Launchpad Bug:

Description


Change History (2)

comment:1 Changed at 2012-01-09T04:17:42Z by warner

  • Milestone changed from undecided to 1.9.1
  • Owner changed from somebody to warner
  • Status changed from new to assigned

comment:2 Changed at 2012-04-01T23:43:38Z by warner

  • Milestone changed from 1.9.2 to 1.9.1
  • Resolution set to fixed
  • Status changed from assigned to closed

1.9.1 tarballs in the release directory are signed, using a keyid 2048R/68666A7A, with fingerprint E34E 62D0 6D0E 69CF CA41 79FF BDE0 D31D 6866 6A7A. The full pubkey is:

-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1.4.12 (GNU/Linux)

mQENBE8OLPEBCACjlqwJ2nDJ8erLap76iVwYs3ayzvq2WSc6KE6G8QPiC71caJBo
JYwoaySVnNPotEjPNXc3yz+a4fSQB8SEkRlZ1PLq3aOwH5xeSvwul5hZaR4Q6Uq1
aKg2wtT8DWF4xTh/wQc+vktU01tmXAgMoQADJ7VQ6zxVR+3P8F7txwTOnhpS94kV
P7TgEHGwRpqoYe87bz7LkUwl/tPTg6wEM2r08/JSN9svoQ3J5YADI5/Z7oP6+5/n
q94SRVwSl5Bh1AWnLFrPM6VOuEJC3wQhpPYYXG21GvLds+p9ywlnl114K/HOqjF7
LuNNHD8g+PusloRLrotCn38XKr7SKhhj5lUlABEBAAG0N1RhaG9lLUxBRlMgUmVs
ZWFzZS1TaWduaW5nIEtleSAoaHR0cHM6Ly90YWhvZS1sYWZzLm9yZymJATgEEwEC
ACIFAk8OLPECGwMGCwkIBwMCBhUIAgkKCwQWAgMBAh4BAheAAAoJEL3g0x1oZmp6
GWMH/1K1gg8s5U/r/A582VvlGDh2HvM4TDgxI+8Of9jVjyyts9Y95GNks99KDlXV
J4b/paZa7kl50UHFYw5xJxW4K9wBsHSxVi6D/xyW6qzxmbTY+IVDGGoInjytQxeZ
RODRHphcA4tPC1Hjbi8cROky/bh+phpZHNpwpreimD2KBw8EHxSCQiUtlf0ahmgG
kH+Xg9A7kaJKQAAP2Q79VEcqrl899Ma1zeMseaLVoN82IBD7flh6FKiTkenAMlCi
91y+uj16q+CCie4yU8od8nCxBRwkIDGyE7DXh5a2sKIlsQMduZbLHOmSLJlqYZnI
gAp2wfH1ttwpUpbmZo1zy7WYGJC5AQ0ETw4s8QEIAOpN5XwXPj4PxzmEv9FII21c
qU3xtpwQFHoZhS0QweOXCGZc5ZaZghr8aLfKfc9hy6rKXUxF5Sa7bhG48Ggs+wuU
REDgepflF3B5V80NeMcH6m/G+yp/HmBtROoLiOvZG8RmWDI8iwP7byI434L2avR1
0EWrPUOn0ma7WK5bKqvsnbF03uoAWqQa9FJldb3SUnJEmg6kR2YzkPelIOW9Qqls
6tLuMrkvcQJbgLoDCtqoGFmJ89CNEP07cL5t2hwb/+nQ/uickFOE8v7310m6yo4A
rzo2+whwYp6MQ92nvJ3qSBNOyeDjRf5fj5aacJJSnWMJLPx4zSkjbI2rWMg09K0A
EQEAAYkBHwQYAQIACQUCTw4s8QIbDAAKCRC94NMdaGZqeoHTCACWCclxAU4j9RV8
dmP4cqCR2ojw0ciS0EOt+zW9iHqIuAgM6gh/t6mGNzCE1lTyGZuORQxK8cRj4w4G
eTY2jBXjyUSuktRHV5QcDUBKqKyhqOpXDriBVFu2TlN67aecfgW6b22dh+k/K+J8
0lMjTyqNOvwDM6bDjENuTleM1cfejqKMaD6ezkJbJI1oVbIbmPJALdgalt5B7xqm
sG1Nw/lKAFWZgUROxxSs3UlG3Tm2R9qD/oM+hTbyHe/bfu+lI3Nw4Q+iRG+TzvzQ
NXk7bu8sU1MU15uPYdpTU5qS1F64UQ7hQFxaix5x+ZxS8A4zr4B3uii0sKT7/dzp
6z/sBCD2
=YnH+
-----END PGP PUBLIC KEY BLOCK-----

Subsequent releases will be signed with this key too.

Note: See TracTickets for help on using tickets.