AMD General The updated key should be available on keys.openpgp.org and the QEMU website now.
Let me know if there are any issues. Thanks for catching this! -Mike From: LOUIS NAUDE <[email protected]> Sent: Tuesday, September 22, 2026 3:02 PM To: Roth, Michael <[email protected]>; [email protected] Subject: Re: QEMU 11.1.1 release-signing key expiry — request for authoritative updated key You don't often get email from [email protected]<mailto:[email protected]>. Learn why this is important<https://aka.ms/LearnAboutSenderIdentification> Hi Mike, Thank you for confirming—that’s very helpful. Could you please let us know once the updated public key is available, and where we should retrieve it? We’ll then refresh our copy, confirm the fingerprint and updated expiry information, and complete verification of the release archive. Thanks again for your help. Kind regards, Louis Naude From: "Roth, Michael" <[email protected]<mailto:[email protected]>> Date: Tuesday, 22 September 2026 at 21:48 To: LOUIS NAUDE <[email protected]<mailto:[email protected]>>, "[email protected]<mailto:[email protected]>" <[email protected]<mailto:[email protected]>> Subject: RE: QEMU 11.1.1 release-signing key expiry — request for authoritative updated key AMD General You are doing everything right, I was not aware my key had expired. I’ll get this updated, but for the current releases on the site the key on the website is the key used for the signing. Thanks, Mike From: LOUIS NAUDE <[email protected]<mailto:[email protected]>> Sent: Tuesday, September 22, 2026 2:01 PM To: [email protected]<mailto:[email protected]> Cc: Roth, Michael <[email protected]<mailto:[email protected]>> Subject: QEMU 11.1.1 release-signing key expiry — request for authoritative updated key Importance: High You don't often get email from [email protected]<mailto:[email protected]>. Learn why this is important<https://aka.ms/LearnAboutSenderIdentification> Hello QEMU maintainers, I contacted Michael directly yesterday and am widening this question to the project list in case another maintainer can help. We are preparing to verify qemu-11.1.1.tar.xz before using it. The QEMU download page identifies this release-signing fingerprint: CEACC9E15534EBABB82D3FA03353C9CEF108B584 The keyserver copy retrieved on 21 September 2026 reports expiry on 11 May 2026 at 15:13:07 UTC. The detached signature qemu-11.1.1.tar.xz.sig records a creation time of 27 August 2026 at 14:16:47 UTC. We have inspected that packet metadata but have not yet verified the signature against the source archive, so we are not treating the timestamp as authenticated. Could you please confirm: 1. Is an updated copy of the same signing key, containing an authenticated expiry extension, available from an authoritative location? 2. If not, what is the intended verification procedure for this release? 3. Is another release maintainer available to help resolve this? This is blocking our verification step. We are not seeking to bypass signature checks; we need the correct verification material and procedure. Thank you for your assistance. Kind regards, Louis Naude
