News: Announce: verifications of GPG signed files in the download areas
[110 news in archive]
Announce: verifications of GPG signed files in the download areas
Item posted by Mathieu Roy <yeupou> on Tue 28 Jun 2005 05:06:51 PM UTC.
To improve security, there will be automated verification of GPG signed files contained in projects download areas soon.
Projects will not be forced to sign their files, indeed, but encouraged to do so. Signed files that could not be verified will be moved in subdirectories named /maybe-corrupted.
This automated check is not in production yet since it appears that several projects have GPG signed files that cannot be verified because their project members have not registered their GPG key through Savane yet.
Automated checks will be activated next week so it is important that projects members register their GPG keys at https://gna.org/account/change.php?item=gpgkey
If you want to know more about this issue, check the FAQ.
The verification failed for the following files:
-------------------------------------------------------
backtolife/backtolife-0.1.0.tar.gz
backtolife/backtolife-0.1.1.tar.gz
backtolife/backtolife-0.1.2.tar.gz
balazar/Balazar-0.0.2.tar.bz2
balazar/Balazar-0.1.tar.bz2
balazar/Balazar-with-deps-0.1.tar.gz
bpp/bpp-0.1-20050428.tar.gz
cbb/cbb-0.8.0.tar.gz
cbb/cbb-0.8.1.tar.gz
cbb/cbb-0.9.5b.tgz
guile-lib/guile-lib-0.1.2.tar.gz
pcbb/cbb-0.7.9a.tar.gz
quarry/quarry-0.1.6.tar.gz
quarry/quarry-0.1.7.tar.gz
quarry/quarry-0.1.9.tar.gz
renamer/renamer-0.2.tar.bz2
renamer/renamer-0.3.tar.bz2
renamer/renamer.tar.bz2
rtai/experimental/fusion-0.1.tar.bz2
rtai/experimental/fusion-0.2.tar.bz2
rtai/experimental/fusion-0.3.tar.bz2
rtai/experimental/fusion-0.4.tar.bz2
rtai/experimental/fusion-0.5.tar.bz2
rtai/experimental/fusion-0.6.1.tar.bz2
rtai/experimental/fusion-0.6.2.tar.bz2
rtai/experimental/fusion-0.6.3.tar.bz2
rtai/experimental/fusion-0.6.4.tar.bz2
rtai/experimental/fusion-0.6.5.tar.bz2
rtai/experimental/fusion-0.6.6.tar.bz2
rtai/experimental/fusion-0.6.7.tar.bz2
rtai/experimental/fusion-0.6.8.tar.bz2
rtai/experimental/fusion-0.6.9.tar.bz2
rtai/experimental/fusion-0.6.tar.bz2
rtai/experimental/fusion-0.7.1.tar.bz2
rtai/experimental/fusion-0.7.2.tar.bz2
rtai/experimental/fusion-0.7.3.tar.bz2
rtai/experimental/fusion-0.7.4.tar.bz2
rtai/experimental/fusion-0.7.5.tar.bz2
rtai/experimental/fusion-0.7.tar.bz2
rtai/experimental/fusion-0.8.1.tar.bz2
rtai/experimental/fusion-0.8.tar.bz2
rtai/nightly/showroom-v3.x-20050616.tar.bz2
rtai/stable/v1/rtai-1.0.tar.bz2
rtai/stable/v1/rtai-1.1b.tar.bz2
rtai/stable/v1/rtai-1.2a.tar.bz2
rtai/stable/v1/rtai-1.3a.tar.bz2
rtai/stable/v1/rtai-1.4.tar.bz2
rtai/stable/v1/rtai-1.5.tar.bz2
rtai/stable/v1/rtai-1.6.tar.bz2
rtai/stable/v1/rtai-1.7.tar.bz2
rtai/stable/v2/rtai-24.1.0.tar.bz2
rtai/stable/v2/rtai-24.1.1.tar.bz2
rtai/stable/v2/rtai-24.1.10.tar.bz2
rtai/stable/v2/rtai-24.1.11.tar.bz2
rtai/stable/v2/rtai-24.1.12.tar.bz2
rtai/stable/v2/rtai-24.1.13.tar.bz2
rtai/stable/v2/rtai-24.1.2.tar.bz2
rtai/stable/v2/rtai-24.1.3.tar.bz2
rtai/stable/v2/rtai-24.1.4.tar.bz2
rtai/stable/v2/rtai-24.1.5.tar.bz2
rtai/stable/v2/rtai-24.1.6a.tar.bz2
rtai/stable/v2/rtai-24.1.7.tar.bz2
rtai/stable/v2/rtai-24.1.8.tar.bz2
rtai/stable/v2/rtai-24.1.9.tar.bz2
rtai/stable/v3/rtai-3.0.tar.bz2
rtai/stable/v3/rtai-3.0r2.tar.bz2
rtai/stable/v3/rtai-3.0r3.tar.bz2
rtai/stable/v3/rtai-3.0r4.tar.bz2
rtai/stable/v3/rtai-3.0r5.tar.bz2
rtai/stable/v3/rtai-3.1.tar.bz2
rtai/stable/v3/rtai-3.1r2.tar.bz2
rtai/stable/v3/rtai-3.2.tar.bz2
rtai/testing/fusion/fusion-0.8.1.tar.bz2
rtai/testing/fusion/fusion-0.8.tar.bz2
rtai/testing/v3/rtai-3.0-test1.tar.bz2
rtai/testing/v3/rtai-3.0-test2.tar.bz2
rtai/testing/v3/rtai-3.0-test3.tar.bz2
rtai/testing/v3/rtai-3.1-test1.tar.bz2
rtai/testing/v3/rtai-3.1-test2.tar.bz2
rtai/testing/v3/rtai-3.1-test3.tar.bz2
rtai/testing/v3/rtai-3.1-test4.tar.bz2
rtai/testing/v3/rtai-3.1-test5.tar.bz2
rtai/testing/v3/rtai-3.2-test1.tar.bz2
rtai/testing/v3/rtai-3.2-test2.tar.bz2
rtai/testing/v3/rtai-3.2-test3.tar.bz2
skatricks/skatricks-0.2.tar.bz2
skatricks/skatricks.tar.bz2
slune/Py2Play-0.1.7.tar.gz
slune/Slune-0.7.tar.bz2
slune/Slune-0.7b.tar.bz2
slune/Slune-1.0.1.tar.bz2
slune/Slune-1.0.2.tar.bz2
slune/Slune-1.0.3.tar.bz2
slune/Slune-1.0.4.tar.bz2
slune/Slune-1.0.5.tar.bz2
slune/Slune-1.0.6.tar.bz2
slune/Slune-1.0.7.tar.bz2
slune/Slune-1.0a.tar.bz2
slune/Slune-1.0rc3.tar.bz2
slune/Slune-with-deps-0.7.tar.gz
slune/Slune-with-deps-0.7b.tar.gz
slune/Slune-with-deps-1.0.1.tar.gz
slune/Slune-with-deps-1.0.4.tar.gz
slune/Slune-with-deps-1.0.5.tar.gz
slune/Slune-with-deps-1.0.6.tar.gz
slune/Slune-with-deps-1.0.7.tar.gz
slune/Slune-with-deps-1.0a.tar.gz
slune/Slune-with-deps-1.0rc3.tar.gz
songwrite/EditObj-0.5.3.tar.gz
songwrite/EditObj-0.5.4.tar.gz
songwrite/EditObj-0.5.5.tar.gz
songwrite/EditObj-0.5.6.tar.gz
songwrite/Songwrite-0.13.tar.gz
soya/Soya-0.7.tar.bz2
soya/Soya-0.7a.tar.bz2
soya/Soya-0.7b.tar.bz2
soya/Soya-0.7c.tar.bz2
soya/Soya-0.8.1.tar.bz2
soya/Soya-0.8.2.tar.bz2
soya/Soya-0.8a.tar.bz2
soya/Soya-0.8rc2.tar.bz2
soya/Soya-0.8rc3.tar.bz2
soya/Soya-0.9.1.tar.bz2
soya/Soya-0.9.2.tar.bz2
soya/Soya-0.9.tar.bz2
soya/SoyaTutorial-0.7.tar.bz2
soya/SoyaTutorial-0.7a.tar.bz2
soya/SoyaTutorial-0.7b.tar.bz2
soya/SoyaTutorial-0.8.1.tar.bz2
soya/SoyaTutorial-0.8.2.tar.bz2
soya/SoyaTutorial-0.8rc2.tar.bz2
soya/SoyaTutorial-0.9.tar.bz2
yopenal/PyOpenAL-0.1.4.tar.gz
Comments:
| Message: 182 |
|---|
|
What if I lost a key? (posted by doublep, Wed 29 Jun 2005 05:34:01 PM UTC) Hello.
I'm the author of Quarry, some files of which listed above. I used a different key for them, but then lost it (in an HDD crash.) Is there anything I can do? If the files are going to forcedly go to a subdirectory, I can as well take them down as those versions are really old.
Or, perhaps, I could reconstruct the tarballs from the CVS and sign them with the new key...
|
| Thread | Author | Date |
|---|---|---|
| doublep | Wed 29 Jun 2005 05:34:01 PM UTC | |
| | doublep | Wed 29 Jun 2005 05:35:37 PM UTC |
| | yeupou | Thu 30 Jun 2005 04:17:14 PM UTC |

