From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.io!.POSTED.blaine.gmane.org!not-for-mail From: Eli Zaretskii Newsgroups: gmane.emacs.help Subject: Re: Public key for verifying emacs sources? Date: Sun, 18 Jul 2021 15:05:03 +0300 Message-ID: <83o8az7rps.fsf@gnu.org> References: <20210718014431.GA18267@srevilak.net> <83mtqk2jj7.fsf@gnu.org> Injection-Info: ciao.gmane.io; posting-host="blaine.gmane.org:116.202.254.214"; logging-data="26533"; mail-complaints-to="usenet@ciao.gmane.io" To: help-gnu-emacs@gnu.org Original-X-From: help-gnu-emacs-bounces+geh-help-gnu-emacs=m.gmane-mx.org@gnu.org Sun Jul 18 14:06:01 2021 Return-path: Envelope-to: geh-help-gnu-emacs@m.gmane-mx.org Original-Received: from lists.gnu.org ([209.51.188.17]) by ciao.gmane.io with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1m55YW-0006hb-Te for geh-help-gnu-emacs@m.gmane-mx.org; Sun, 18 Jul 2021 14:06:00 +0200 Original-Received: from localhost ([::1]:44902 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1m55YV-0001ar-Py for geh-help-gnu-emacs@m.gmane-mx.org; Sun, 18 Jul 2021 08:05:59 -0400 Original-Received: from eggs.gnu.org ([2001:470:142:3::10]:39758) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1m55Y7-0001Ys-If for help-gnu-emacs@gnu.org; Sun, 18 Jul 2021 08:05:35 -0400 Original-Received: from fencepost.gnu.org ([2001:470:142:3::e]:42470) by eggs.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1m55Y7-0006DE-8u for help-gnu-emacs@gnu.org; Sun, 18 Jul 2021 08:05:35 -0400 Original-Received: from 84.94.185.95.cable.012.net.il ([84.94.185.95]:3642 helo=home-c4e4a596f7) by fencepost.gnu.org with esmtpsa (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1m55Xk-0006Yc-QH for help-gnu-emacs@gnu.org; Sun, 18 Jul 2021 08:05:33 -0400 In-Reply-To: (message from Jean Louis on Sun, 18 Jul 2021 14:38:07 +0300) X-BeenThere: help-gnu-emacs@gnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: Users list for the GNU Emacs text editor List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: help-gnu-emacs-bounces+geh-help-gnu-emacs=m.gmane-mx.org@gnu.org Original-Sender: "help-gnu-emacs" Xref: news.gmane.io gmane.emacs.help:131826 Archived-At: > Date: Sun, 18 Jul 2021 14:38:07 +0300 > From: Jean Louis > Cc: help-gnu-emacs@gnu.org > > * Eli Zaretskii [2021-07-18 10:02]: > > > Date: Sat, 17 Jul 2021 21:44:31 -0400 > > > From: Steve Revilak > > > > > > Where can I find a copy of the signing key, so I can verify the source > > > distribution I've downloaded? > > > > Download the latest gnu-keyring.gpg from > > https://ftp.gnu.org/gnu/gnu-keyring.gpg, then type: > > > > gpg --import gnu-keyring.gpg > > > > Then try verifying the signature again. > > Me too, I have done the import and I see large number of keys. While > it is good that keys are distributed from official GNU.org server, > there is no published assurance that GNU project verified each key to > belong to the person it should belong. Thus one shall not forget > security depends on the weakest part. Please take this up with the GNU FTP site maintainers. I didn't upload my key to any place, I sent them my key and asked for upload rights. I don't know what they did with the key. This issue doesn't belong on this forum anyway.