Re: KEYS file?

2016-07-12 Thread Steve Loughran
On 11 Jul 2016, at 04:48, Shuai Lin > wrote: at least links to the keys used to sign releases on the download page +1 for that. really all release keys for ASF projects should be signed by others in the project and the broader ASF

Re: KEYS file?

2016-07-11 Thread Sean Owen
Yeah the canonical place for a project's KEYS file for ASF projects is http://www.apache.org/dist/{project}/KEYS and so you can indeed find this key among: http://www.apache.org/dist/spark/KEYS I'll put a link to this info on the downloads page because it is important info. On Mon, Jul 11,

Re: KEYS file?

2016-07-10 Thread Shuai Lin
> > at least links to the keys used to sign releases on the > download page +1 for that. On Mon, Jul 11, 2016 at 3:35 AM, Phil Steitz wrote: > On 7/10/16 10:57 AM, Shuai Lin wrote: > > Not sure where you see " 0x7C6C105FFC8ED089". I > > That's the key ID for the key

Re: KEYS file?

2016-07-10 Thread Phil Steitz
On 7/10/16 10:57 AM, Shuai Lin wrote: > Not sure where you see " 0x7C6C105FFC8ED089". I That's the key ID for the key below. > think the release is signed with the > key https://people.apache.org/keys/committer/pwendell.asc . Thanks! That key matches. The project should publish a KEYS file [1]

Re: KEYS file?

2016-07-10 Thread Shuai Lin
Not sure where you see " 0x7C6C105FFC8ED089". I think the release is signed with the key https://people.apache.org/keys/committer/pwendell.asc . I think this tutorial can be helpful: http://www.apache.org/info/verification.html On Mon, Jul 11, 2016 at 12:57 AM, Phil Steitz