Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Where is the public key to check the pgp signature of nqp tarballs ? #426

Closed
dod38fr opened this issue Feb 23, 2018 · 2 comments
Closed
Assignees

Comments

@dod38fr
Copy link

dod38fr commented Feb 23, 2018

Hello

Debian strongly suggests to verify the signature of upstream tarballs. Each release of nqp is signed, which is good.

Unfortunately, I cannot find the pgp public key of this signature.

Could you tell me where I can find this pubilc key ? (it may be simpler for you to upload your public key to a pgp key server)

All the best

@AlexDaniel
Copy link
Member

OK, so my key can be found here: https://keybase.io/alexdaniel (it links to multiple sources so that you can cross-verify).
Same key is also on my github account: https://api.github.com/users/AlexDaniel/gpg_keys

In case that's not enough I also submitted the key to pgp.mit.edu server that you mentioned.

Please close if that's enough, or let me know what can be done better.

@dod38fr
Copy link
Author

dod38fr commented Feb 24, 2018

I've retrieved the key from pgp.mit.edu, that's the most simple for me.

Download and gpg verification now works fine. :-)

Thanks for the help

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants