Please verify your email address with keys.openpgp.org so that users can download your key.
Problem
It's great that your project signs your releases with pgp using key = [email protected].
Unfortunately, it's not well documented which key is used to sign your releases. This key should be available for download on many key servers and well-integrated into the Web-of-Trust.
It's great that I can find your key on Ubuntu's keyservers
However, it's trivial for an attacker to create another key with uid = [email protected]. As such, your documentation should specify the full fingerprint of the key, for which an attacker cannot create a conflicting key = 3B9191625F3B1F1BF5DD3B47673A02042F6B6B7F.
(See also related ticket wp-cli/handbook#584)
Unfortunately, certificate spamming attacks have made old sks keyservers vulnerable. It's recommended that you use a modern keyserver that strips signature data:
I see your key has been uploaded to this server, but the email address was never verified. Therefore, users cannot download your key from the above keyserver.
Error: Verifying your email address…
Solution
Please verify your email address with keys.openpgp.org
Please verify your email address with
keys.openpgp.orgso that users can download your key.Problem
It's great that your project signs your releases with pgp using key =
[email protected].Unfortunately, it's not well documented which key is used to sign your releases. This key should be available for download on many key servers and well-integrated into the Web-of-Trust.
It's great that I can find your key on Ubuntu's keyservers
However, it's trivial for an attacker to create another key with uid =
[email protected]. As such, your documentation should specify the full fingerprint of the key, for which an attacker cannot create a conflicting key =3B9191625F3B1F1BF5DD3B47673A02042F6B6B7F.(See also related ticket wp-cli/handbook#584)
Unfortunately, certificate spamming attacks have made old sks keyservers vulnerable. It's recommended that you use a modern keyserver that strips signature data:
I see your key has been uploaded to this server, but the email address was never verified. Therefore, users cannot download your key from the above keyserver.
Solution
Please verify your email address with keys.openpgp.org