AMD General You are doing everything right, I was not aware my key had expired.
I’ll get this updated, but for the current releases on the site the key on the website is the key used for the signing. Thanks, Mike From: LOUIS NAUDE <[email protected]> Sent: Tuesday, September 22, 2026 2:01 PM To: [email protected] Cc: Roth, Michael <[email protected]> Subject: QEMU 11.1.1 release-signing key expiry — request for authoritative updated key Importance: High You don't often get email from [email protected]<mailto:[email protected]>. Learn why this is important<https://aka.ms/LearnAboutSenderIdentification> Hello QEMU maintainers, I contacted Michael directly yesterday and am widening this question to the project list in case another maintainer can help. We are preparing to verify qemu-11.1.1.tar.xz before using it. The QEMU download page identifies this release-signing fingerprint: CEACC9E15534EBABB82D3FA03353C9CEF108B584 The keyserver copy retrieved on 21 September 2026 reports expiry on 11 May 2026 at 15:13:07 UTC. The detached signature qemu-11.1.1.tar.xz.sig records a creation time of 27 August 2026 at 14:16:47 UTC. We have inspected that packet metadata but have not yet verified the signature against the source archive, so we are not treating the timestamp as authenticated. Could you please confirm: 1. Is an updated copy of the same signing key, containing an authenticated expiry extension, available from an authoritative location? 2. If not, what is the intended verification procedure for this release? 3. Is another release maintainer available to help resolve this? This is blocking our verification step. We are not seeking to bypass signature checks; we need the correct verification material and procedure. Thank you for your assistance. Kind regards, Louis Naude
