Hello QEMU maintainers,

I contacted Michael directly yesterday and am widening this question to the 
project list in case another maintainer can help.

We are preparing to verify qemu-11.1.1.tar.xz before using it. The QEMU 
download page identifies this release-signing fingerprint:

CEACC9E15534EBABB82D3FA03353C9CEF108B584

The keyserver copy retrieved on 21 September 2026 reports expiry on 11 May 2026 
at 15:13:07 UTC.

The detached signature qemu-11.1.1.tar.xz.sig records a creation time of 27 
August 2026 at 14:16:47 UTC. We have inspected that packet metadata but have 
not yet verified the signature against the source archive, so we are not 
treating the timestamp as authenticated.

Could you please confirm:
Is an updated copy of the same signing key, containing an authenticated expiry 
extension, available from an authoritative location?
If not, what is the intended verification procedure for this release?
Is another release maintainer available to help resolve this?
This is blocking our verification step. We are not seeking to bypass signature 
checks; we need the correct verification material and procedure.

Thank you for your assistance.

Kind regards,
Louis Naude

 

Reply via email to