xpra icon
Bug tracker and wiki

This bug tracker and wiki are being discontinued
please use https://github.com/Xpra-org/xpra instead.


Opened 3 months ago

Last modified 5 weeks ago

#2968 assigned task

move to new signing keys

Reported by: Antoine Martin Owned by: Antoine Martin
Priority: major Milestone: 4.2
Component: external Version: 3.0.x
Keywords: Cc:

Description

Instead of signing the packages with my personal key, create a new one (stronger too) for the project and ensure that other trusted developers can take it over if needed.
(and store it on a hardware token to keep it safe)

The difficult part is going to be the transition, as packages can only be signed by a single key.
New packages could just add the new signing key to the system (ie: rpm --import) and eventually (6 months?) we can switch over to the new key without causing too many problems?

Change History (2)

comment:2 Changed 5 weeks ago by migration script

this ticket has been moved to: https://github.com/Xpra-org/xpra/issues/2968

Note: See TracTickets for help on using tickets.