https://bz.apache.org/bugzilla/show_bug.cgi?id=70200
--- Comment #4 from Rod Widdowson <[email protected]> --- Thanks I got a GPG-wise colleague to talk me through this. I ended up taking the keys from the website (which do *NOT*have this new key in them) and doing an update from a couple of keyservers using the 160 bit keyID (the full one means that there is an effective zero chance of spoofing) It might help others if some stage you updated the keys on your website to include ther version of BC26C53AF531F8B4B3F5930AAFBD3AF8EAFA72DA with the D7C40DE43 as a subkey. Thanks again. I'll make this as resolved -- You are receiving this mail because: You are the assignee for the bug.
