Closed joannafarley-arm closed 5 years ago
I've been maintaining arm-trusted-firmware in Debian, and would like to figure out a trust path for updated versions...
I see that the v2.1 tag is gpg-signed, but with a public key not present in the gpg keyring network, so a bit hard to independently verify. Github apparently knows about the key, as it's marking it as verified, though I can't seem to find any way to get github to give me the public key.
Would it be possible to publish the public key used for signing releases somewhere?
live well, vagrant
H Vagrant,
Just wanted to let you know I’m working on a solution for you.
Regards
Joanna
Hi Vagrant,
The public key has been uploaded to http://keyserver.pgp.com/ and is available there and hopefully will be distributed round the gpg keyring network.
Let me know if you have any issues.
Regards
Joanna
@vagrantc I hope Joanna's solution works for you. Closing this ticket for now.
Trusted Firmware version 2.1 is now available and can be found here: https://github.com/ARM-software/arm-trusted-firmware/tree/v2.1
Please refer to the readme and change log for further information.
Regards
Joanna