AMD General

The updated key should be available on keys.openpgp.org and the QEMU website 
now.

Let me know if there are any issues.

Thanks for catching this!

-Mike

From: LOUIS NAUDE <[email protected]>
Sent: Tuesday, September 22, 2026 3:02 PM
To: Roth, Michael <[email protected]>; [email protected]
Subject: Re: QEMU 11.1.1 release-signing key expiry — request for authoritative 
updated key

You don't often get email from 
[email protected]<mailto:[email protected]>. Learn why this is 
important<https://aka.ms/LearnAboutSenderIdentification>
Hi Mike,
Thank you for confirming—that’s very helpful.
Could you please let us know once the updated public key is available, and 
where we should retrieve it? We’ll then refresh our copy, confirm the 
fingerprint and updated expiry information, and complete verification of the 
release archive.
Thanks again for your help.
Kind regards,
Louis Naude


From: "Roth, Michael" <[email protected]<mailto:[email protected]>>
Date: Tuesday, 22 September 2026 at 21:48
To: LOUIS NAUDE <[email protected]<mailto:[email protected]>>, 
"[email protected]<mailto:[email protected]>" 
<[email protected]<mailto:[email protected]>>
Subject: RE: QEMU 11.1.1 release-signing key expiry — request for authoritative 
updated key


AMD General

You are doing everything right, I was not aware my key had expired.

I’ll get this updated, but for the current releases on the site the key on the 
website is the key used for the signing.

Thanks,

Mike

From: LOUIS NAUDE <[email protected]<mailto:[email protected]>>
Sent: Tuesday, September 22, 2026 2:01 PM
To: [email protected]<mailto:[email protected]>
Cc: Roth, Michael <[email protected]<mailto:[email protected]>>
Subject: QEMU 11.1.1 release-signing key expiry — request for authoritative 
updated key
Importance: High

You don't often get email from 
[email protected]<mailto:[email protected]>. Learn why this is 
important<https://aka.ms/LearnAboutSenderIdentification>

Hello QEMU maintainers,

I contacted Michael directly yesterday and am widening this question to the 
project list in case another maintainer can help.

We are preparing to verify qemu-11.1.1.tar.xz before using it. The QEMU 
download page identifies this release-signing fingerprint:

CEACC9E15534EBABB82D3FA03353C9CEF108B584

The keyserver copy retrieved on 21 September 2026 reports expiry on 11 May 2026 
at 15:13:07 UTC.

The detached signature qemu-11.1.1.tar.xz.sig records a creation time of 27 
August 2026 at 14:16:47 UTC. We have inspected that packet metadata but have 
not yet verified the signature against the source archive, so we are not 
treating the timestamp as authenticated.

Could you please confirm:

  1.  Is an updated copy of the same signing key, containing an authenticated 
expiry extension, available from an authoritative location?
  2.  If not, what is the intended verification procedure for this release?
  3.  Is another release maintainer available to help resolve this?

This is blocking our verification step. We are not seeking to bypass signature 
checks; we need the correct verification material and procedure.

Thank you for your assistance.

Kind regards,
Louis Naude

Reply via email to