Skip to content

Commit

Permalink
Merge pull request #120 from mwestphall/SOFTWARE-5664-osg-23-signing-…
Browse files Browse the repository at this point in the history
…keys

SOFTWARE-5664: Document the OSG 23 package signing public keys
  • Loading branch information
mwestphall authored Aug 25, 2023
2 parents f87069f + 30497b7 commit 712d0e6
Show file tree
Hide file tree
Showing 3 changed files with 130 additions and 0 deletions.
52 changes: 52 additions & 0 deletions docs/release/RPM-GPG-KEY-OSG-23-auto
Original file line number Diff line number Diff line change
@@ -0,0 +1,52 @@
-----BEGIN PGP PUBLIC KEY BLOCK-----

mQINBGSVtzUBEACbpnE9afL1mMzgkl0G7oHnt/17FOTOjIdfRzftdxcUQ3o+wwFn
EVpi99blxDNt2pP5ba63bpRSzfgyB8G+B8Y5GFcN452Qc4VgyrEQmJMJxk2F0XqM
I6o2uAYNDa2/5nI5wtgrKC2nT/kqbqFsSmKsm9/5aC7LlSzcO7YlA/ZnKgVRYNI/
PDE53pchFFTsvSY7+qsDZraogwVQBU+4XTGRdaW/ZNKAaHxy5IHH2PYFl8U+QmKF
8VR9kNsHQie6RYWjpuhauX4Zo0TXZMgDNLllI3vQSJuTzuL67s29nWJUKyBeA/cZ
IH1S2YeVaos0Q1Y1OXU3vfVaWrdhB3rennD/lZBiLZlA6+0BNqbGPDyPzRIaypCY
EWlmU7qQw/gM+WbVNO+Zk+RvNQ62J9LgyOoezPLNWj2RAtmVrI1ACvMl9LB3N+T5
IohVWgcM5wgZCcBO8GIXLfxCuMelUwaiPJdH2DqydK0Dz44FEq8QneoN5Kd09R4P
VtoPiNJAoebVRLLZEvgEwEoWTXGSfimYlELfPPpWtD+mN9m2y8z0+Ku4b6Cw5rFu
V4UTE5igf7aTb7DabcQnx149tPYFK40A7PRdX228W77LNfWt92U4QqVrMPS3b1R5
77RWg5jnIYj7pFQDrU+OaNMtbWH8W0lRiu1gUbHAiVhOT0ZdlMN5yqkm/wARAQAB
tC9PU0cgMjMgQXV0b21hdGVkIFNpZ25pbmcgS2V5IDxoZWxwQG9zZy1odGMub3Jn
PokCUgQTAQgAPBYhBOKvn24jn9YrU3cFwBdg7fZNQ4TQBQJktYQvAhsDBQsJCAcC
AyICAQYVCgkICwIEFgIDAQIeBwIXgAAKCRAXYO32TUOE0N1tD/9V6XtsAsTA9ert
6d1pG7Zj4jc6iiAhrM2JCeOji/X5cf9XVpuCS6f0hpcXrF2tkSXAZFH3YlYMlK++
dqcm4QfTx2F1oKcrbEroKL3IY1B/vWL3ca1kM30EtlHGqMq8as5qAw72QE4RJR5e
6IMxhky2B1jmk3N6Ba4nf1IazGapx9xBSBnmMKI2Y//JdYDSj1HpmJ3Ac5FydfDy
h2++5h8eSkEgXjUCgEDQDZKXljUECxgpwk6I/HJqdu/d2/wR5ZV4t+U+h2tiXzAo
bV5Ocy87D8IX/Sz86vDHjGYpmQe836aulaPkd81rq9Fkv/gvcCh00Q88SZ0rSWKi
43y+mmqWOnOdnnit4DH5g5L7XLWNuMtSVULZZlB8LcTE86scJCD0gMxV434Tzpq3
Jm627kh9Gjul0IRhV20/WeGm8u8cBIUrBEuGSdG0KCyodM5JZ3mm2b8cnatx+SZW
vrqOVYMd0Ml69m+r5z0L6aH+FovBU8m9yEn45WeM3qDLdexmDVy8vsrC9pvCIDmc
IsetQzjeYgzPF7uqG9Xdb3S1YP8pArO4EwYAWRGrgld+nzdU2POzS51m6j9jMZQv
xM9NEUBFzFKjuyBcjEinKY4umr4TnXwMeA0VVBCqZzDTPgazMNuwpiykCHnsqRva
x9nLc6zqO2UsMcP9KosoKIt50oTad7kCDQRklbc1ARAAlleAib4pRoKPo4NVHqdB
FvBL891dkKJrFyEU4yfjDWWjLOS9HDC2kfuX0DKMGpczOqPGCiAz8BUl5aWOiX2z
An0v9ptrlTTWmzvEC0Lv/wZ7JBHsXmjjbAoAeJPAQCnVto9OmwSxRVrR5OxeySv/
fig16W4KuwqUNLjoW5jmTWzZfZ2AVP2UtNvmy+Eim8ZovANJjODmQHS5GAzUr53b
uN0DKyVXtqbJ1qZmneybkOE/6rM0Zc/U/JPN6MbkpbKp/LXcpFb60XS+kWHS0H6W
Cz3NmzsXXx68CCii8dRhWC4zFzSdL/quxVmtPJToWbAZ1a4HSA3mA0KtDGOwjt/w
aO0kxZ9U83ZjS35PngEp07Ws6IEb8ucpKXaSEFX80TDK7F44LyUh6iqSH+Gg0v5Q
+k065U9o4NPzbHcBcOqZfS5+pqVG+P42+nzHbv8XzvL3B1KMQvBXdWHy5sFHQACf
gM0d4rdffjVAuIJ5vkV2UFBry0DY11Lkcu9zk5aK0dYulkSWV69z1G9GHtLGcOaz
8unYGNCcSREaJYSQo8zNlpv+MERwtMsGJ9mN2WWi3+fNtaXVfVfA4toVYVCkK/lx
nXD8hc+5Ga42fRjwz1uV3bYmPMx+pRmT2Veld+bfJBol2cU+HpH+W5Ka8B/45l+F
Gnda82iGySF6DJZ5l9CX7+kAEQEAAYkCNgQYAQgAIBYhBOKvn24jn9YrU3cFwBdg
7fZNQ4TQBQJklbc1AhsMAAoJEBdg7fZNQ4TQP+sP/0U78ePKc4kWbezE1KIeU/3b
fj3WUbhW35DZ039Dr4lk7PUt85dSvjPu5DCmzqGbaHg00ZGBYY+XAtKdT0r2emkr
06Smv+Ey7BLpeeYP3ZVtiPq54e/IsWeHxXoE35Xq+n0CSfa7Z8LGswJte0LeZ803
bqTt2y4zU3wPrdtaTtg50oWrZNt9UQSyAB2biBgrOSVwwAVksmoSaVigOnJEjLSz
YiTP+apPOu4xXdjuKAV7fHOBDIQSMMkWQuArf05O5ZX3H/4H0fTHkO8BD2bcsgHP
FdJQApLvA+9fduKN2NSEjWSMUU4BsIdKU/7kn4SDi4ki+tGMWjW6uF114WpVRyPl
40cp3oQQO+w1qBW5AwwSHd6bPsg6uXll/pNHSwN/fJe9ETtFIogrvp35ogNAKvTs
7h5U6RX1G1kMDKLhSnFvJlEHrlQpnz+WNtwUgkrc4HwUsqeWXDuYQ1eUVuAqomy3
+CqmNzt6/ow0S7zPVqG3dJRoqrgoRcWjJl7NX2zloV3qTnjb0YDejw+8c6azD80v
S8k9PO8EjSDxpLMxW/np2rIYO94lsZuBoFwXwqc8ldaeQdS4Ayg2a21i64FENApD
ZGoTP2r9oIE3Julx3yhSTEM82IkE2I9OPwIrpHrzlbcXaWNPS2Yd85/F3ihUbUAD
EwhCOov5UFCIgkctf6Zq
=BaNC
-----END PGP PUBLIC KEY BLOCK-----
52 changes: 52 additions & 0 deletions docs/release/RPM-GPG-KEY-OSG-23-developer
Original file line number Diff line number Diff line change
@@ -0,0 +1,52 @@
-----BEGIN PGP PUBLIC KEY BLOCK-----

mQINBGTbseYBEACztKzZcDcw9KTywt0fW70pnBUw2bA3vG4lLmoh9WAaPD2L0Uyj
P7OmkIK9xSkosmeTar7BE0Qb444oMOK0YgSg6gzxFXGlsOLtrlpQmQfhGVCxHs7q
Jm9Tw9VwuMwwmJqGjh2Ny5hV6m3sfB0M//TozZSMBdBzx59z572gvupr4lxfuaWH
o9RuzJW2RoXVtNaVEIs8J8wjLjTWHEVM4rcE+qc9ebMFD3IZ6snX3vgxW9fxeyvT
FkaNn7U6ynWsLCgKLnzd19bj8i6BiJXnqAr48Pfvg84GESZsLP4EmqGu1YrwlYcz
xMQjh+6/xktw6rcwOf+8PGq9mX5g06O6xZxUthxC9HggqwhXr8E4cq1104QuqAqc
Y9oMvRyzRUStMfFKzA7lNf2VWgLNBBdwo+cd1rHDEJQ81zeryLyJJcB7jbyP5gzn
S4mctx7WuS/Lm29utSrOtabjayaXHUoX7VuSybZa5vuG3/wx5e4+Fgpa2oU3kk7u
QWEBFBoTjRjVhoyTeBNXFvtj1RtsnztXzscitq/ym87gPpSphalpRuVSfx5XEk6g
BetioAoIgK4ggt0VDs4+wxfyfPbqoLoKary96l6JidFkAC30hpS1f0AledRr/S3D
Jl1Aevue0+hNnULggDHuV/l/+sxC3NKa5F9iqRVN0IIdPLJLuf3fnmxzAQARAQAB
tDBPU0cgMjMgRGV2ZWxvcGVyIFNpZ25pbmcgS2V5IDxoZWxwQG9zZy1jaHRjLm9y
Zz6JAlIEEwEIADwWIQRKVsW7zbCqot3pppC97uJMkol8AAUCZNux5gIbAwULCQgH
AgMiAgEGFQoJCAsCBBYCAwECHgcCF4AACgkQve7iTJKJfACl9A/+PTN5VXmLhXLd
32FC+WO9ntkorORGIODlxTelLcsp2C6Dgll2Wxub7xLg9mPuISrCTMH8ELBWPfAA
dlC0pyFE9ObcHa0N4y07k/v72nzeJt3bCNNEd0+7IYHp7c2Ju3h2G0OyQFSS+FRn
5+/wUsZDdgmKZXd8zpE1hn/GYA9RfmXcUKfh2zwDHg2kPrUomGa46hqLneKurYHS
9eiQkknguEjhRfzTjzHxhAt1V13fj3Xzjb9Emn7ItRlENopSlG/pY/+sB+5d6xt3
0DeEN1QuQeYLyCcvb6v6HQU5wnTEQCl7rz6UgMgYEqO6cEeADCCpYsUD7sgpgwnB
71T30J7Q5FEnWIMCRdWhYBEz5YiQO1Zpq2wVrY6+rCk86e05z7u+a94py1tj95xr
IKnTp7vwPSzqsyXi79gKQqFvSD3H3C8DRIyW2pFiiYG4rDR28rVxaF7qneM3mdwX
YLtMKTQsO7DIMhbBDhkzByImrsB6WxTGJiNw96drwrLv/Jx7PtQu8JaCWbmsNxXv
vGnGTb5bSG9V5Gr+9oR9LgJyT8UPIigxcv2FCeul63z1ij7ZzkZISCM2eLIgSa2P
w7+qW95p6yEMgtN2w9AFtC1Bx/8haDRP9/CAvx3DqQtt1lT5Z9yHiuG4Fy3RUgV3
rdKod3RlJ24GW5HjWqy9JxiGlKt0vT+5Ag0EZNux5gEQALFIRECs+q6MGIQb8YDz
VyiZtwA/MIlYc0/3BH4KJemlKmOm0Y/MGo6jlCOhxRHw6mfNC0LTrOgieW9UXdR8
zeTgrvMmP8+TAIo/hQIsRL94Rrz9+6WkS3lpyskDQkC/dUu30QUP0vGFZ9Xui55V
7ogZMSvA56Oc1eyy7C0ZxPEFT9GX3lMjwyk76dsSSh1BGBafmeTifxNMmUJ5uGUX
0EyEiB5duwt/BGFkNi0iqvJylTf2l2FS62RTaXW6QBidtfk5SIQNCxZF5vxgbD1Y
BG/DQP9U2YyyoyLhnhEnwROPqSQjBZ0hh8DfpsKzRYwgBLHKdiFkj8s27K4HlbzP
qKXOBzRry5RF1hnbF3iHiKiLRo9N2fG93SbjwQDThOHcfBsKb1oQpU+qECDFsAku
1NYjGo11AX+595IBWflaMCpx0Adz9ItLLsfr9PTfooohREoihlpyy1Zq04fy7I7Y
C16LA0D7ZiMKLemH8gPyr1FIXxaFaeqYr3NVw0EYXGFbYdixDidyQ9qj5sop077B
2ffSyBeuvMYwY02AKinUUwfztFddWRZKFuVJolfrK1BO9UUtY6Z0Y8WDfzs5T+Zo
FKqwf8AnxSiSfJnuYVJWWWfnBbhnDc2QExB8SDrAFDscrdxpJNue6ywouKPbzCVo
bzqBeIaHPHGB1+U1FYlTO7jjABEBAAGJAjYEGAEIACAWIQRKVsW7zbCqot3pppC9
7uJMkol8AAUCZNux5gIbDAAKCRC97uJMkol8ALHND/9VaSv6VISs1i6yzE4XPhfF
/NQQftiXWvSY6Qj26FkGUXtneMgHmglCnlWrL9kOtZQy6Mo/12THbm+51pWJe/60
/04/aNi+z3FMJlTHvkd2jMakpI2SVtMZbvqnncSJgXKw+R1UUNTpdFnq9hI4+PUn
aLzxjod8pnbRRhmZd8Pn9a/uNqQ2q1/B1B4MaZlrBKtBHuNt35/uNCZWFXCgkL/I
lsSuS4cFyr/yoBlCsZPHSsavdRJEGryH04dxayc4qQFyCkuhaXW/E72nAYiy2My/
uY0U7G5ZeF71GpROJL5IGXORs163wAPs2ywtzbdVNzqk1t2qVSI6rOHLjFd8V3xx
U8z63kBoEMF2bLrQzfWdURI4yc4pZmgZU5YzoEVdzQF66mtzfaKKV8EleYQYe1eN
rKH9QplN8aPJmaMQvHmQSSsbmpA2+saqG71kkpg04I+gOPraa2CFgRfwCKaPDHVS
nGVKuhsGpHaRJ4pff4VZexJ3B65z19rrMcsA9mxDzBCs3kZ+XJI2Lio6iVd/yPFD
ke+r9UMuLoB1loiW56+4aAfqrXDc8BrbmzN44FQHwXoFiFH7MpA0ohmbVPhzQwKR
mLWnKrgkZWynVeTRRn1jtKlOa/mPuBqHODcuVcbLE8vUmS9dvDLn/CiaJqexeNav
+aG4TP7q2/1t7Z2kyPBJTQ==
=w0oq
-----END PGP PUBLIC KEY BLOCK-----
26 changes: 26 additions & 0 deletions docs/release/signing.md
Original file line number Diff line number Diff line change
Expand Up @@ -53,6 +53,20 @@ The key used depends on the OSG version and EL variant used, as documented below
| Fingerprint | `B77E 70A6 0537 1D3B E109 A18E 3170 E150 1887 C61A` |
| Key ID | `1887c61a` |

| OSG 23 Automated Signing Key | |
|--------------------|--------------------------------------------------------|
| Location | `/etc/pki/rpm-gpg/RPM-GPG-KEY-OSG-23-auto` |
| Download | [GitHub](https://raw.githubusercontent.com/opensciencegrid/docs/master/docs/release/RPM-GPG-KEY-OSG-23-auto) |
| Fingerprint | `E2AF 9F6E 239F D62B 5377 05C0 1760 EDF6 4D43 84D0` |
| Key ID | `4d4384d0` |

| OSG 23 Developer Signing Key | |
|--------------------|--------------------------------------------------------|
| Location | `/etc/pki/rpm-gpg/RPM-GPG-KEY-OSG-23-developer` |
| Download | [GitHub](https://raw.githubusercontent.com/opensciencegrid/docs/master/docs/release/RPM-GPG-KEY-OSG-23-developer) |
| Fingerprint | `4A56 C5BB CDB0 AAA2 DDE9 A690 BDEE E24C 9289 7C00` |
| Key ID | `92897c00` |

!!! note
Some packages in the 3.6 repos may still be signed with the old key;
the `osg-release` RPM contains both keys so you can verify old packages.
Expand Down Expand Up @@ -92,5 +106,17 @@ pub rsa4096 2022-12-28 [SC]
uid OSG Software 3.6 for EL9 RSA <help@osg-htc.org>
sub rsa4096 2022-12-28 [E]

$ gpg --import-options show-only --import < /etc/pki/rpm-gpg/RPM-GPG-KEY-OSG-23-auto
pub rsa4096 2023-06-23 [SC]
E2AF9F6E239FD62B537705C01760EDF64D4384D0
uid OSG 23 Automated Signing Key <help@osg-htc.org>
sub rsa4096 2023-06-23 [E]

$ gpg --import-options show-only --import < /etc/pki/rpm-gpg/RPM-GPG-KEY-OSG-23-developer
pub rsa4096 2023-08-15 [SC]
4A56C5BBCDB0AAA2DDE9A690BDEEE24C92897C00
uid OSG 23 Developer Signing Key <help@osg-chtc.org>
sub rsa4096 2023-08-15 [E]

```

0 comments on commit 712d0e6

Please sign in to comment.