[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [bug-gnu-libiconv] libiconv signing key
From: |
Bruno Haible |
Subject: |
Re: [bug-gnu-libiconv] libiconv signing key |
Date: |
Sat, 31 Oct 2020 19:54:19 +0100 |
User-agent: |
KMail/5.1.3 (Linux/4.4.0-193-generic; KDE/5.18.0; x86_64; ; ) |
[CCing the mailing list]
Hello,
George Rawlinson wrote:
> The key used to sign libiconv (version 1.16) has expired.
>
> I believe it is this key: 68D94D8AAEEAD48AE7DC5B904F494A942E4616C2.
Thanks for reporting this, but:
A key expiry is something else than a key revocation.
Keys eventually expire, yet signatures previously made with them remain
valid pieces of information. As long as the signature was made before
the key expired (which you can infer by looking at the timestamp of
the file on ftp.gnu.org - even if you don't trust the date in the signature
itself), you can trust the signature.
Bruno
- Re: [bug-gnu-libiconv] libiconv signing key,
Bruno Haible <=