Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Public key for verification of download expired #7264

Open
polymorphito opened this issue Sep 30, 2024 · 4 comments
Open

Public key for verification of download expired #7264

polymorphito opened this issue Sep 30, 2024 · 4 comments

Comments

@polymorphito
Copy link

Hey guys,

the public GNU key of Alejandro Garcia on your website for verification of Bisq downloads has expired with 27/09/2024. Could you please replace it with a key up to date?

Or is there no reason to worry about that?

Looking forward to an answer, best regards

Chris

Copy link

boring-cyborg bot commented Sep 30, 2024

Thanks for opening your first issue here!

Be sure to follow the issue template. Your issue will be reviewed by a maintainer and labeled for further action.

@dauphinet
Copy link

I am having the same issue!
kleopatra

gpg: Signature faite le 06/24/24 02:54:15 Paris
gpg: avec la clef RSA 987654321
gpg: Bonne signature de « Alejandro García [email protected] » [expirée]
gpg: Remarque : cette clef a expiré.
Empreinte de clef principale : 123456789

@ncorbuk
Copy link

ncorbuk commented Oct 13, 2024

yes im verifying and i come here to check and it seems the key is old from June what is this all about?

@suddenwhipvapor
Copy link
Contributor

The verification works correctly following the instructions on https://github.com/bisq-network/bisq/releases/tag/v1.9.18
Just tested myself:

gpg: assuming signed data in 'Bisq-64bit-1.9.18.deb'
gpg: Signature made ven 22 nov 2024, 20:36:15 CET
gpg:                using RSA key B493319106CC3D1F252E19CBF806F422E222AA02
gpg: Good signature from "Alejandro García <[email protected]>" [unknown]
gpg: WARNING: This key is not certified with a trusted signature!
gpg:          There is no indication that the signature belongs to the owner.
Primary key fingerprint: B493 3191 06CC 3D1F 252E  19CB F806 F422 E222 AA02

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

7 participants
@ncorbuk @dauphinet @suddenwhipvapor @polymorphito and others