Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Specify public key for verifying signatures for downloaded tarball releases #212

Open
ullbeking opened this issue Mar 4, 2021 · 0 comments
Assignees
Labels
documentation Improvements or additions to documentation
Milestone

Comments

@ullbeking
Copy link

I've not submitted a PR because I don't know how the signer would like this to be specified.

I downloaded https://github.com/notqmail/notqmail/releases/download/notqmail-1.08/notqmail-1.08.tar.gz and https://github.com/notqmail/notqmail/releases/download/notqmail-1.08/notqmail-1.08.tar.gz.sig recently. I wanted to verify the gzipped tarball according to the signature but there was no link to the public key so that I can use gpg --verify to use public-key cryptography to verify the download.

I ended up asking around in IRC, then doing a Google search for a username that I don't know anything about. I'm new to the qmail world. I ended up finding the (apparently) real name of the person who signed the tarball. I then searched for their name on Google to find their public key fingerprint, and finally used gpg --search-keys to download the public key from a keyserver while hoping that the public keyserver system is presently working.

I know how to use GPG. The problem was that I didn't know which public key to install to verify the signature. It would be very useful to include this in the installation instructions.

Like I mentioned, I would have written the PR myself, but it's not my key and after a recent conversation in #qmail on Freenode, it seems to me that it would be better to leave this to the signer. I would be happy to help write this piece of documentation, however, so if I can help, let me know.

@DerDakon DerDakon added the documentation Improvements or additions to documentation label Mar 4, 2021
@DerDakon DerDakon self-assigned this Mar 4, 2021
@schmonz schmonz added this to the 1.09.1 milestone Feb 1, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
documentation Improvements or additions to documentation
Projects
None yet
Development

No branches or pull requests

3 participants