Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security: release signing public key: missing and expires 1 August 2024 #749

Open
iam-TJ opened this issue Jun 13, 2024 · 0 comments
Open

Comments

@iam-TJ
Copy link

iam-TJ commented Jun 13, 2024

In attempting to verify the source package signatures at

https://dist.opendnssec.org/source/

for both softhsm2 and opendnssec I am unable to find any mention of the release signing key.

In the Debian source package there is an apparent copy of the public key that in its header reports:

#
# OpenDNSSec distribution keys. The keys are published at:
# https://wiki.opendnssec.org/display/OpenDNSSEC/PGP
#

# Distribution key 2017
# Valid from 2017-01-11 and expires 2024-08-01

But I've been unable to find the public key published securely by opendnssec.

I also found the existing key expired once before in November 2022, the Debian package maintainer reported it [0] and although there was no reply to that mailing-list report the expiry date of the key was apparently extended.

$ gpg  ./opendnssec-2.1.13/debian/upstream/signing-key.asc
gpg: WARNING: no command supplied.  Trying to guess what you mean ...
pub   rsa4096 2017-01-11 [SC] [expires: 2024-08-01]
4D0388CE86BB398B387B663041F623BE4FCB0B94
uid           OpenDNSSEC Distribution Key 2017 <[email protected]>

[0] https://lists.opendnssec.org/pipermail/opendnssec-user/2022-November/004716.html

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant