swebb2066 commented on code in PR #313:
URL: https://github.com/apache/logging-log4net/pull/313#discussion_r3911781450


##########
scripts/verify-release.ps1:
##########
@@ -55,16 +59,20 @@ foreach ($Artifact in $Artifacts)
   Assert-Hash $Artifact
 }
 
-Invoke-WebRequest https://downloads.apache.org/logging/KEYS -OutFile 
$Directory/KEYS
-
 # A key ring of its own, holding only the downloaded KEYS. Importing into the 
default key ring
 # would accept a signature from any key this machine already has, not only 
from a key in the
 # Logging Services KEYS file.
 $KeyringDirectory = New-Item -ItemType Directory -Path (Join-Path 
([System.IO.Path]::GetTempPath()) ([guid]::NewGuid()))
 try
 {
+  # Downloaded into that directory, and never read from the one being 
verified: a KEYS file sitting
+  # next to the artifacts is not covered by any of the checks above, so 
importing it would let
+  # anyone who can place a file there have their own key accepted as a release 
key.
+  $Keys = Join-Path $KeyringDirectory 'KEYS'
+  Invoke-WebRequest https://downloads.apache.org/logging/KEYS -OutFile $Keys
+
   $Keyring = Join-Path $KeyringDirectory 'logging-keys.gpg'
-  gpg --no-default-keyring --keyring $Keyring --batch --quiet --import 
$Directory/KEYS
+  gpg --no-default-keyring --keyring $Keyring --batch --quiet --import $Keys

Review Comment:
   I recieved the following warning when using the script to verfiy 3.4.0
   `gpg: Note: Specified keyrings are ignored due to option "use-keyboxd"`
   
   It seems gpg then ignores the --keyring file  



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to