Making PGP distribution key well-known

Kevin Fenzi kevin at scrye.com
Fri Mar 2 16:46:55 UTC 2012


On Fri, 2 Mar 2012 12:53:35 +0000 (UTC)
Petr Pisar <ppisar at redhat.com> wrote:

> On 2012-03-01, Michal Schmidt <mschmidt at redhat.com> wrote:
> > Dne 1.3.2012 17:52, Petr Pisar napsal(a):
> >> where to get public key for verifying RPM signatures.
> >
> > The keys are at: https://fedoraproject.org/keys
> >
> And F16 primary key (A82BA4B7) is signed by... 1 guy. Awesome.
> 
> And ISO images propagated on Fedora web pages have signatures where?
> I see, one must trim the URL manually and hope the web server lists
> directory and there will be a signature.

https://fedoraproject.org/en/verify has a full list of them, but yes,
they should be in the same directory. 

If you can think of a better way to present this data, do say. 

kevin
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 836 bytes
Desc: not available
URL: <http://lists.fedoraproject.org/pipermail/devel/attachments/20120302/9bd64209/attachment.sig>


More information about the devel mailing list