File suse-build-key.changes of Package suse-build-key
386
1
-------------------------------------------------------------------
2
Wed Aug 21 15:36:57 UTC 2024 - Marcus Meissner <meissner@suse.com>
3
4
- extended 2048 bit SUSE SLE 12, 15 GA-SP5 key until 2028. (bsc#1229339)
5
- gpg-pubkey-39db7c82-5f68629b.asc
6
+ gpg-pubkey-39db7c82-66c5d91a.asc
7
8
9
-------------------------------------------------------------------
10
Fri Jul 12 12:33:23 UTC 2024 - Marcus Meissner <meissner@suse.com>
11
12
- added missing ; in shell script (bsc#1227681)
13
14
-------------------------------------------------------------------
15
Mon Jul 8 14:31:48 UTC 2024 - Marcus Meissner <meissner@suse.com>
16
17
- Added new keys of the SLE Micro 6.0 / SLES 16 series, and auto import
18
them. (bsc#1227429)
19
gpg-pubkey-09d9ea69-645b99ce.asc: Main SLE Micro 6/SLES 16 key
20
gpg-pubkey-73f03759-626bd414.asc: Backup SLE Micro 6/SLES 16 key.
21
22
-------------------------------------------------------------------
23
Fri Feb 9 12:34:40 UTC 2024 - Marcus Meissner <meissner@suse.com>
24
25
- Switch container key to be default RSA 4096bit. (jsc#PED-2777)
26
27
-------------------------------------------------------------------
28
Sun Jan 28 15:24:55 UTC 2024 - Marcus Meissner <meissner@suse.com>
29
30
- run rpm commands in import script only when libzypp is not
31
active. bsc#1219189 bsc#1219123
32
33
-------------------------------------------------------------------
34
Sun Jan 28 15:24:55 UTC 2024 - Marcus Meissner <meissner@suse.com>
35
36
- run import script also in %posttrans section, but only when
37
libzypp is not active. bsc#1219189 bsc#1219123
38
39
-------------------------------------------------------------------
40
Thu Nov 16 12:50:14 UTC 2023 - Marcus Meissner <meissner@suse.com>
41
42
- replace libzypp-post-script based installation with a systemd timer
43
and service.
44
- suse-build-key-import.service
45
- suse-build-key-import.timer
46
47
-------------------------------------------------------------------
48
Fri Sep 8 09:41:33 UTC 2023 - Marcus Meissner <meissner@suse.com>
49
50
- add and run a import-suse-build-key scripts, this will be ran
51
after installation with libzypp based installers. (jsc#PED-2777)
52
53
-------------------------------------------------------------------
54
Tue Feb 7 10:41:12 UTC 2023 - Marcus Meissner <meissner@suse.com>
55
56
- Establish multiple new 4096 RSA keys that we will switch
57
to mid of 2023. (jsc#PED-2777)
58
- gpg-pubkey-3fa1d6ce-63c9481c.asc: new 4096 RSA signing key for SLE (RPM+repos).
59
- gpg-pubkey-d588dc46-63c939db.asc: new 4096 RSA reserver key for SLE (RPM+repos).
60
- suse_ptf_key_4096.asc: new 4096 RSA signing key for PTF RPMs.
61
- build-container-8fd6c337-63c94b45.asc/build-container-8fd6c337-63c94b45.pem:
62
new RSA 4096 key for the SUSE registry registry.suse.com, installed as
63
suse-container-key-2023.pem and suse-container-key-2023.asc
64
- suse_ptf_containerkey_2023.asc suse_ptf_containerkey_2023.pem:
65
New PTF container signing key for registry.suse.com/ptf/ space.
66
67
-------------------------------------------------------------------
68
Tue Oct 25 12:19:09 UTC 2022 - Marcus Meissner <meissner@suse.com>
69
70
- added /usr/share/pki/containers directory for container pem keys
71
(cosign/sigstore style), put our PEM key there too (bsc#1204706)
72
73
-------------------------------------------------------------------
74
Thu Apr 21 12:47:26 UTC 2022 - Marcus Meissner <meissner@suse.com>
75
76
- still ship the old ptf key (was not added to documentation by mistake).
77
(bsc#1198504)
78
79
-------------------------------------------------------------------
80
Thu Mar 24 09:07:52 UTC 2022 - Marcus Meissner <meissner@suse.com>
81
82
- No longer install 1024bit keys by default. (bsc#1197293)
83
- SLE11 key moved to documentation
84
- old PTF (pre March 2022) moved to documentation only
85
86
-------------------------------------------------------------------
87
Thu Feb 17 12:28:49 UTC 2022 - Marcus Meissner <meissner@suse.com>
88
89
- extended expiry of SUSE PTF key, move it to suse_ptf_key_old.asc
90
- added new SUSE PTF key with RSA2048 bit as suse_ptf_key.asc (bsc#1196494)
91
- extended expiry of SUSE SLES11 key (bsc#1194845)
92
- added SUSE Contaner signing key in PEM format for use e.g. by cosign.
93
- SUSE security key replaced with 2022 edition (E-Mail usage only). (bsc#1196495)
94
95
-------------------------------------------------------------------
96
Mon Sep 21 08:30:03 UTC 2020 - Marcus Meissner <meissner@suse.com>
97
98
- suse build key extended (bsc#1176759)
99
gpg-pubkey-39db7c82-5847eb1f.asc -> gpg-pubkey-39db7c82-5f68629b.asc
100
101
102
-------------------------------------------------------------------
103
Thu Aug 13 09:32:26 UTC 2020 - Marcus Meissner <meissner@suse.com>
104
105
- actually the container key is different from the build signing
106
key. (PM-1845 bsc#1170347)
107
108
-------------------------------------------------------------------
109
Thu Apr 23 13:32:45 UTC 2020 - Marcus Meissner <meissner@suse.com>
110
111
- add a /usr/share/container-keys/ directory for GPG based Container
112
verification.
113
- Add the SUSE build key as "suse-container-key.asc". (PM-1845 bsc#1170347)
114
115
-------------------------------------------------------------------
116
Wed Mar 11 09:09:42 UTC 2020 - Marcus Meissner <meissner@suse.com>
117
118
- created a new security@suse.de communication key (bsc#1166334)
119
120
-------------------------------------------------------------------
121
Tue Nov 13 12:41:24 UTC 2018 - meissner@suse.com
122
123
- include ptf key in the key directory to avoid it being
124
stripped via %doc stripping. (bsc#1044232)
125
126
-------------------------------------------------------------------
127
Wed Mar 28 14:56:15 UTC 2018 - meissner@suse.com
128
129
- created a new security@suse.de communication key. (bsc#1082022)
130
- extended the PTF key and the SLE10 build@suse.de key. (bsc#1085512)
131
132
-------------------------------------------------------------------
133
Wed Dec 7 16:35:05 UTC 2016 - meissner@suse.com
134
135
- extend the build@suse.de product key. (bsc#1014151)
136
137
pub 2048R/39DB7C82 2013-01-31 [expires: 2020-12-06]
138
uid SuSE Package Signing Key <build@suse.de>
139
140
-------------------------------------------------------------------
141
Tue Nov 29 12:54:46 CET 2016 - ro@suse.de
142
143
- use dumpsigs script from openSUSE to merge code
144
145
-------------------------------------------------------------------
146
Thu Oct 2 12:45:05 UTC 2014 - meissner@suse.com
147
148
- renamed security_at_suse_de.asc to security_at_suse_de_old.asc
149
- security_at_suse_de.asc: new 4096 bit RSA key.
150
pub 4096R/317CD502 2014-10-02 SUSE Security Team <security@suse.de>
151
bnc#899509
152
153
-------------------------------------------------------------------
154
Fri Aug 29 08:28:03 UTC 2014 - meissner@suse.com
155
156
- Went to new method again.
157
- suse-build-key.gpg blob dropped
158
- ship seperate files
159
160
-------------------------------------------------------------------
161
Mon Feb 10 09:57:50 UTC 2014 - meissner@suse.com
162
163
- create suse-build-key.gpg during build.
164
- Remove old keys from keyring. (fate#314767)
165
Keys currently inside the RPM trusted keyring:
166
- pub 2048R/39DB7C82 SuSE Package Signing Key <build@suse.de>
167
- pub 2048R/50A3DD1C SuSE Package Signing Key (reserve key) <build@suse.de>
168
- Various keys are moved to the documentation area
169
(/usr/share/doc/packages/suse-build-key)
170
- build-at-suse-sle11.asc: the old SUSE Linux Enterprise 11 key.
171
if SUSE Linux Enterprise 11 packages need to be verified on
172
a SUSE Linux Enterprise 12 system.
173
- suse_ptf_key.asc: The suse ptf key. For verification of provided PTFs.
174
- security_at_suse_de.asc: Use only for email encryption and
175
verification purposes when contacting our security contact address
176
security@suse.de
177
178
-------------------------------------------------------------------
179
Mon Jan 13 15:01:24 UTC 2014 - meissner@suse.com
180
181
- reverted to contain the fullkeyring build SLE12 Alpha.
182
- also list the old sle11 build@suse.de key temporary
183
184
-------------------------------------------------------------------
185
Thu Jan 9 12:29:53 UTC 2014 - meissner@suse.com
186
187
- Merged over logic from openSUSE-build-key.
188
- Got rid of default importing into roots keyring.
189
- Removed some old keys.
190
- Clarify that security@suse.de is a email only key
191
- PTF key is supplied also as %doc, to not be default
192
imported.
193
- Keys currently inside:
194
- pub 2048R/39DB7C82 SuSE Package Signing Key <build@suse.de>
195
- pub 2048R/50A3DD1C SuSE Package Signing Key (reserve key) <build@suse.de>
196
- pub 1024D/B37B98A9 SUSE PTF Signing Key <support@suse.com>
197
- pub 2048R/3D25D3D9 SuSE Security Team <security@suse.de>
198
199
-------------------------------------------------------------------
200
Thu Jan 31 17:11:08 CET 2013 - ro@suse.de
201
202
- added future signing key for SLES (fate#314767) (bnc#801055)
203
using 2048 bit rsa key
204
205
-------------------------------------------------------------------
206
Mon Jan 14 01:55:36 CET 2013 - ro@suse.de
207
208
- added reserve key for SLES (fate#312896)
209
50A3DD1C SuSE Package Signing Key (reserve key) <build@suse.de>
210
valid until (2017-01-13)
211
212
-------------------------------------------------------------------
213
Sun Oct 21 23:03:01 CEST 2012 - ro@suse.de
214
215
- export keys to single files in /usr/lib/rpm/gnupg/keys
216
217
-------------------------------------------------------------------
218
Mon Dec 12 12:02:49 CET 2011 - ro@suse.de
219
220
- reduced key list. remaining keys:
221
307E3D54 SuSE Package Signing Key <build@suse.de>
222
3D25D3D9 SuSE Security Team <security@suse.de>
223
9C800ACA SuSE Package Signing Key <build@suse.de>
224
B37B98A9 SUSE PTF Signing Key <support@suse.com>
225
226
-------------------------------------------------------------------
227
Fri Jan 28 13:02:42 CET 2011 - ro@suse.de
228
229
- if we have to set $HOME, we also have to export the variable
230
(bnc#665912)
231
232
-------------------------------------------------------------------
233
Tue May 4 16:11:41 CEST 2010 - ro@suse.de
234
235
- updated keys: (bnc#600157,bnc#599167)
236
- 307E3D54 build@suse.de "SuSE Package Signing Key" (2014-05-03)
237
- 9C800ACA build@suse.de "SuSE Package Signing Key" (2014-05-03)
238
- B37B98A9 support@suse.com "SUSE PTF Signing Key" (2014-05-03)
239
- 7E2E3B05 novell-provo-build@novell.com "Novell Provo Build"
240
(2014-05-06)
241
- added keys:
242
- 1D061A62 support@novell.com
243
"build@novell.com (Novell Linux Products)" (2014-05-06)
244
245
-------------------------------------------------------------------
246
Fri Oct 31 14:28:18 CET 2008 - ro@suse.de
247
248
- added ptf key, expiring 2010-07-02
249
250
-------------------------------------------------------------------
251
Mon Jun 2 15:45:33 CEST 2008 - ro@suse.de
252
253
- update keys again: for collaboration with rpm, the current
254
self-signature needs to be the first signature found in a key
255
256
-------------------------------------------------------------------
257
Mon May 5 18:31:20 CEST 2008 - ro@suse.de
258
259
- updated keys
260
9C800ACA,8495160C,307E3D54: extend expiration by 2 years
261
until 2010-05-05
262
7E2E3B05: extend expiration by 2 years until 2010-05-24
263
264
-------------------------------------------------------------------
265
Mon Mar 19 16:49:05 CET 2007 - rguenther@suse.de
266
267
- merge suse-build-key keyring to roots gpg pubring
268
269
-------------------------------------------------------------------
270
Mon May 29 17:20:45 CEST 2006 - ro@suse.de
271
272
- added new official provo dsa autobuild key ID 7E2E3B05
273
274
-------------------------------------------------------------------
275
Fri May 19 14:02:59 CEST 2006 - ro@suse.de
276
277
- removed unused provo autobuild key
278
- added new official provo autobuild key ID A1912208
279
280
-------------------------------------------------------------------
281
Thu Apr 20 12:47:18 CEST 2006 - ro@suse.de
282
283
- add dumpsigs script here to have _one_ place for the script
284
285
-------------------------------------------------------------------
286
Fri Mar 31 16:53:02 CEST 2006 - ro@suse.de
287
288
- added build@suse.de rsa key ID 307E3D54
289
290
-------------------------------------------------------------------
291
Wed Jan 25 21:47:54 CET 2006 - mls@suse.de
292
293
- converted neededforbuild to BuildRequires
294
295
-------------------------------------------------------------------
296
Tue Oct 18 17:47:07 CEST 2005 - ro@suse.de
297
298
- use correct provo autobuild key
299
300
-------------------------------------------------------------------
301
Tue Oct 18 12:28:04 CEST 2005 - ro@suse.de
302
303
- added provo autobuild signing key (#128128)
304
- removed jds key
305
306
-------------------------------------------------------------------
307
Fri May 27 14:47:30 CEST 2005 - mls@suse.de
308
309
- added mktemp to PreReqs [#86177]
310
311
-------------------------------------------------------------------
312
Thu Apr 28 11:45:36 CEST 2005 - ro@suse.de
313
314
- added JDS public key (15c17deb)
315
316
-------------------------------------------------------------------
317
Tue Jan 25 18:10:26 CET 2005 - ro@suse.de
318
319
- added OES public key (0dfb3188)
320
321
-------------------------------------------------------------------
322
Tue Jun 22 12:28:07 CEST 2004 - ro@suse.de
323
324
- updated build key (expiration changed to 2008-06-21) (#42326)
325
326
-------------------------------------------------------------------
327
Tue Feb 24 12:19:49 CET 2004 - hmacht@suse.de
328
329
- building as non-root
330
331
-------------------------------------------------------------------
332
Tue Sep 9 18:51:02 CEST 2003 - ro@suse.de
333
334
- ignore return code from first gpg calls
335
336
-------------------------------------------------------------------
337
Tue Sep 9 18:23:07 MEST 2003 - draht@suse.de
338
339
- call gpg twice without any arguments for proper initialization
340
inside postinstall
341
342
-------------------------------------------------------------------
343
Tue Sep 9 17:43:55 MEST 2003 - draht@suse.de
344
345
- use temp file instead of pipe due to resource race between two
346
instances of gpg in %post.
347
348
-------------------------------------------------------------------
349
Thu Sep 5 04:56:32 CEST 2002 - draht@suse.de
350
351
- package now installs key from package-owned file into the rpm
352
pubring in %post to allow other key packages to add their keys.
353
354
-------------------------------------------------------------------
355
Tue Aug 20 10:46:52 CEST 2002 - mmj@suse.de
356
357
- Correct PreReq
358
359
-------------------------------------------------------------------
360
Fri Jul 26 09:50:14 CEST 2002 - kukuk@suse.de
361
362
- Change Provides from suse-build-key to build-key
363
364
-------------------------------------------------------------------
365
Thu Feb 21 00:10:52 MET 2002 - draht@suse.de
366
367
- directory permission problem: 644 -> 755.
368
369
-------------------------------------------------------------------
370
Mon Feb 18 12:16:34 CET 2002 - ro@suse.de
371
372
- moved to /usr/lib/rpm/gnupg/pubring.pgp
373
rpm needs a directory as gpg_path and will use pubring.gpg
374
in that directory
375
376
-------------------------------------------------------------------
377
Wed Feb 13 20:45:46 MET 2002 - draht@suse.de
378
379
- initial package. Contains
380
- pub 2048R/3D25D3D9 1999-03-06 SuSE Security Team <security@suse.de>
381
382
- pub 1024D/9C800ACA 2000-10-19 SuSE Package Signing Key <build@suse.de>
383
- sub 2048g/8495160C 2000-10-19 [expires: 2006-02-12]
384
385
386