PGP key changing

Damien Miller djm at mindrot.org
Wed Dec 18 14:33:28 EST 2013


On Tue, 17 Dec 2013, Daniel Kahn Gillmor wrote:

> On Thu 2013-12-12 21:56:33 -0500, Damien Miller wrote:
> > I'm rotating my PGP keys, so this is a forewarning that the key used to
> > sign the next release of portable OpenSSH will be different to the one
> > I've used in the past.
> 
> Thanks for the heads-up, Damien, and thanks for doing this boring
> maintenance work and announcing it clearly ahead of time.
> 
> I note that some of the OpenSSH mirrors have DJM-GPG-KEY.asc, which i
> think is the old one.  e.g.
> 
>   http://mirrors.nycbug.org/pub/OpenBSD/OpenSSH/portable/DJM-GPG-KEY.asc
> 
> Maybe you could update the key on the mirrors too when you get a chance.

I was going to leave that one there until I make a release signed with
the new key. Otherwise, people who get the key for the first time ahead
of the release will see "key superseded" deprecation warnings.

-d


More information about the openssh-unix-dev mailing list