Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

GPG signing key for 19.0.3 #22783

Closed
nblock opened this issue Sep 10, 2020 · 3 comments
Closed

GPG signing key for 19.0.3 #22783

nblock opened this issue Sep 10, 2020 · 3 comments
Labels
0. Needs triage Pending check for reproducibility or if it fits our roadmap bug

Comments

@nblock
Copy link
Contributor

nblock commented Sep 10, 2020

The download website at https://nextcloud.com/install/#instructions-server references the signature key at https://nextcloud.com/nextcloud.asc. The fingerprint for this key is: 2880 6A87 8AE4 23A2 8372 792E D758 99B9 A724 937A and all releases except 19.0.3 have been signed with this key. However, the tarball https://download.nextcloud.com/server/releases/nextcloud-19.0.3.tar.bz2 and the respective detached signature from https://download.nextcloud.com/server/releases/nextcloud-19.0.3.tar.bz2.asc have been signed with A438DC095967A1F11601CC42B69CB7F1069B3399.

Steps to reproduce

  1. Import nextcloud signing key from https://nextcloud.com/nextcloud.asc
  2. Download 19.0.3 release: https://download.nextcloud.com/server/releases/nextcloud-19.0.3.tar.bz2
  3. Download the detached signature: https://download.nextcloud.com/server/releases/nextcloud-19.0.3.tar.bz2.asc
  4. Verify: gpg --verify nextcloud-19.0.3.tar.bz2.asc

Expected behaviour

The release should be signed with the offered signing key.

Actual behaviour

The release was signed with a new key, that has not been published on the website.

$ gpg --verify nextcloud-19.0.3.tar.bz2.asc 
gpg: assuming signed data in 'nextcloud-19.0.3.tar.bz2'
gpg: Signature made Wed Sep  9 13:45:51 2020 CEST
gpg:                using RSA key A438DC095967A1F11601CC42B69CB7F1069B3399
gpg: Can't check signature: No public key
@nblock nblock added 0. Needs triage Pending check for reproducibility or if it fits our roadmap bug labels Sep 10, 2020
@kesselb
Copy link
Contributor

kesselb commented Sep 10, 2020

@rullzer 👀

@rullzer
Copy link
Member

rullzer commented Sep 10, 2020

O joy it is picking up the new signing sub key.

@rullzer
Copy link
Member

rullzer commented Sep 10, 2020

Solved. thanks for reporting

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
0. Needs triage Pending check for reproducibility or if it fits our roadmap bug
Projects
None yet
Development

No branches or pull requests

3 participants