martin has asked for the wisdom of the Perl Monks concerning the following question:
I am using Module::Signature and have configured my cpan shell to check signatures (check_sigs=1). This, however, will not just make cpan check module's signatures when unpacking packages, but also make it use my gpg command to check PAUSE checksums. This should perhaps be different configuration options, but I probably would turn both on anyways.
Now Gnu Privacy Guard needs a signer's public key to verify a signed file like a PAUSE generated checksum. This signing key has recently been replaced. I have the old one (328DA867450F89EC) in my keyring but now need the new one (77576125A905F1BA). In https://www.cpan.org/modules/04pause.html , only the old one is present. On keyservers like pgp.mit.edu and keyserver.ubuntu.com the key is not to be found.
Where else should I look? Without the key, I have to use cpan with signature checks completely turned off or it will not install anything. I don't like that. The idea of signatures was to make the toolchain safer against manipulated mirrors. The idea of signed checksums was to protect even packages not signed by their authors. I agree to all of this. Some new way of distributing PAUSE keys may have escaped me, though. Can you fill me in?
Greetings,
-Martin
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Where do I find the current PAUSE batch signing key?
by Perlbotics (Archbishop) on Jul 08, 2023 at 09:52 UTC | |
by martin (Friar) on Jul 08, 2023 at 11:41 UTC | |
by Perlbotics (Archbishop) on Jul 08, 2023 at 17:09 UTC | |
|
More signature problems (was: Where do I find the current PAUSE batch signing key?)
by martin (Friar) on Jul 14, 2024 at 20:35 UTC |