Blame doc/fingerprints.txt

Packit Service 084de1
Fingerprints for Signing Releases
Packit Service 084de1
Packit Service 084de1
OpenSSL releases are signed with PGP/GnuPG keys.  This file contains
Packit Service 084de1
the fingerprints of team members who are "authorized" to sign the
Packit Service 084de1
next release.
Packit Service 084de1
Packit Service 084de1
The signature is a detached cleartxt signature, with the same name
Packit Service 084de1
as the release but with ".asc" appended.  For example, release
Packit Service 084de1
1.0.1h can be found in openssl-1.0.1h.tar.gz with the signature
Packit Service 084de1
in the file named openssl-1.0.1h.tar.gz.asc.
Packit Service 084de1
Packit Service 084de1
The following is the list of fingerprints for the keys that are
Packit Service 084de1
currently in use to sign OpenSSL distributions:
Packit Service 084de1
Packit Service 084de1
pub   4096R/7DF9EE8C 2014-10-04
Packit Service 084de1
      Key fingerprint = 7953 AC1F BC3D C8B3 B292  393E D5E9 E43F 7DF9 EE8C
Packit Service 084de1
uid                  Richard Levitte <richard@opensslfoundation.com>
Packit Service 084de1
uid                  Richard Levitte <levitte@openssl.org>
Packit Service 084de1
uid                  Richard Levitte <richard@openssl.com>
Packit Service 084de1
Packit Service 084de1
pub   2048R/0E604491 2013-04-30
Packit Service 084de1
      Key fingerprint = 8657 ABB2 60F0 56B1 E519 0839 D9C4 D26D 0E60 4491
Packit Service 084de1
uid                  Matt Caswell <matt@openssl.org>
Packit Service 084de1
uid                  Matt Caswell <frodo@baggins.org>