Hello QEMU maintainers, I contacted Michael directly yesterday and am widening this question to the project list in case another maintainer can help.
We are preparing to verify qemu-11.1.1.tar.xz before using it. The QEMU download page identifies this release-signing fingerprint: CEACC9E15534EBABB82D3FA03353C9CEF108B584 The keyserver copy retrieved on 21 September 2026 reports expiry on 11 May 2026 at 15:13:07 UTC. The detached signature qemu-11.1.1.tar.xz.sig records a creation time of 27 August 2026 at 14:16:47 UTC. We have inspected that packet metadata but have not yet verified the signature against the source archive, so we are not treating the timestamp as authenticated. Could you please confirm: Is an updated copy of the same signing key, containing an authenticated expiry extension, available from an authoritative location? If not, what is the intended verification procedure for this release? Is another release maintainer available to help resolve this? This is blocking our verification step. We are not seeking to bypass signature checks; we need the correct verification material and procedure. Thank you for your assistance. Kind regards, Louis Naude
