kpcyrd / rebuilderd

Independent verification of binary packages - reproducible builds
GNU General Public License v3.0
356 stars 26 forks source link

Tails signature verification failure #127

Closed jvoisin closed 2 years ago

jvoisin commented 2 years ago

The tails.sh script hardcodes the Tails gpg key, unfortunately, it needs to be refreshed, but since the signing key weights around ~1.5M, it doesn't seem practical to embed it in the script.

Maybe download it with wget https://tails.boum.org/tails-signing.key, import it into gpg, and hack something with git verify-tag?

jvoisin commented 2 years ago

Fixed by https://github.com/kpcyrd/rebuilderd/pull/128