Signed tags for future petitboot releases

Jeremy Kerr jk at ozlabs.org
Thu Feb 6 03:19:50 AEDT 2020


Hi Joel,

> Are you able to create signed tags for the petitboot releases you
> make?

Sure, can do! Just for future releases, or would you prefer signed tags
for 1.11 and 1.12?

> More importantly, someone is able to check that someone in possession
> of your key created the tag.

Yep, makes sense.

However, my only (non-expired) key at present is super old, and only
1024-bit; looks like I'll need a new one. However, you won't have a
trust path to that. Do I need to fly over to Adelaide for a signing
party? :D

Cheers,


Actual Jeremy



More information about the Petitboot mailing list