change of apache signing key - need my new key signed by others

2022-09-09 Thread Mike Beckerle
I just had to update my apache signing key as it was obsolete (old sha1 algorithm no longer supported) As a result, I now have a new signing key, but no web of trust for it. It would be good if I had some trusted parties sign my new key. Instructions are here: https://cwiki.apache.org/confluence

Re: [jira] [Created] (DAFFODIL-2727) KEYS file contains deprecated digest algorithm, RPM key import failures

2022-09-09 Thread Mike Beckerle
I support just modernizing the current KEYS file, not worrying about people getting a failure when validating older releases using a newer KEYS file. Instructions on how to validate could point this out, i.e., that KEYS technology has changed so older releases require older KEYS files correspondin