Blame doc/fingerprints.txt

Packit c4476c
Fingerprints for Signing Releases
Packit c4476c
Packit c4476c
OpenSSL releases are signed with PGP/GnuPG keys.  This file contains
Packit c4476c
the fingerprints of team members who are "authorized" to sign the
Packit c4476c
next release.
Packit c4476c
Packit c4476c
The signature is a detached cleartxt signature, with the same name
Packit c4476c
as the release but with ".asc" appended.  For example, release
Packit c4476c
1.0.1h can be found in openssl-1.0.1h.tar.gz with the signature
Packit c4476c
in the file named openssl-1.0.1h.tar.gz.asc.
Packit c4476c
Packit c4476c
The following is the list of fingerprints for the keys that are
Packit c4476c
currently in use to sign OpenSSL distributions:
Packit c4476c
Packit c4476c
pub   4096R/7DF9EE8C 2014-10-04
Packit c4476c
      Key fingerprint = 7953 AC1F BC3D C8B3 B292  393E D5E9 E43F 7DF9 EE8C
Packit c4476c
uid                  Richard Levitte <richard@opensslfoundation.com>
Packit c4476c
uid                  Richard Levitte <levitte@openssl.org>
Packit c4476c
uid                  Richard Levitte <richard@openssl.com>
Packit c4476c
Packit c4476c
pub   2048R/0E604491 2013-04-30
Packit c4476c
      Key fingerprint = 8657 ABB2 60F0 56B1 E519 0839 D9C4 D26D 0E60 4491
Packit c4476c
uid                  Matt Caswell <matt@openssl.org>
Packit c4476c
uid                  Matt Caswell <frodo@baggins.org>