File suse-build-key.changes of Package suse-build-key (Revision 6b30f554c5a2dad67a13dde8857911d1)
Currently displaying revision 6b30f554c5a2dad67a13dde8857911d1 , Show latest
365
1
-------------------------------------------------------------------
2
Fri Feb 9 12:34:40 UTC 2024 - Marcus Meissner <meissner@suse.com>
3
4
- Switch container key to be default RSA 4096bit. (jsc#PED-2777)
5
6
-------------------------------------------------------------------
7
Sun Jan 28 15:24:55 UTC 2024 - Marcus Meissner <meissner@suse.com>
8
9
- run rpm commands in import script only when libzypp is not
10
active. bsc#1219189 bsc#1219123
11
12
-------------------------------------------------------------------
13
Sun Jan 28 15:24:55 UTC 2024 - Marcus Meissner <meissner@suse.com>
14
15
- run import script also in %posttrans section, but only when
16
libzypp is not active. bsc#1219189 bsc#1219123
17
18
-------------------------------------------------------------------
19
Thu Nov 16 12:50:14 UTC 2023 - Marcus Meissner <meissner@suse.com>
20
21
- replace libzypp-post-script based installation with a systemd timer
22
and service.
23
- suse-build-key-import.service
24
- suse-build-key-import.timer
25
26
-------------------------------------------------------------------
27
Fri Sep 8 09:41:33 UTC 2023 - Marcus Meissner <meissner@suse.com>
28
29
- add and run a import-suse-build-key scripts, this will be ran
30
after installation with libzypp based installers. (jsc#PED-2777)
31
32
-------------------------------------------------------------------
33
Tue Feb 7 10:41:12 UTC 2023 - Marcus Meissner <meissner@suse.com>
34
35
- Establish multiple new 4096 RSA keys that we will switch
36
to mid of 2023. (jsc#PED-2777)
37
- gpg-pubkey-3fa1d6ce-63c9481c.asc: new 4096 RSA signing key for SLE (RPM+repos).
38
- gpg-pubkey-d588dc46-63c939db.asc: new 4096 RSA reserver key for SLE (RPM+repos).
39
- suse_ptf_key_4096.asc: new 4096 RSA signing key for PTF RPMs.
40
- build-container-8fd6c337-63c94b45.asc/build-container-8fd6c337-63c94b45.pem:
41
new RSA 4096 key for the SUSE registry registry.suse.com, installed as
42
suse-container-key-2023.pem and suse-container-key-2023.asc
43
- suse_ptf_containerkey_2023.asc suse_ptf_containerkey_2023.pem:
44
New PTF container signing key for registry.suse.com/ptf/ space.
45
46
-------------------------------------------------------------------
47
Tue Oct 25 12:19:09 UTC 2022 - Marcus Meissner <meissner@suse.com>
48
49
- added /usr/share/pki/containers directory for container pem keys
50
(cosign/sigstore style), put our PEM key there too (bsc#1204706)
51
52
-------------------------------------------------------------------
53
Thu Apr 21 12:47:26 UTC 2022 - Marcus Meissner <meissner@suse.com>
54
55
- still ship the old ptf key (was not added to documentation by mistake).
56
(bsc#1198504)
57
58
-------------------------------------------------------------------
59
Thu Mar 24 09:07:52 UTC 2022 - Marcus Meissner <meissner@suse.com>
60
61
- No longer install 1024bit keys by default. (bsc#1197293)
62
- SLE11 key moved to documentation
63
- old PTF (pre March 2022) moved to documentation only
64
65
-------------------------------------------------------------------
66
Thu Feb 17 12:28:49 UTC 2022 - Marcus Meissner <meissner@suse.com>
67
68
- extended expiry of SUSE PTF key, move it to suse_ptf_key_old.asc
69
- added new SUSE PTF key with RSA2048 bit as suse_ptf_key.asc (bsc#1196494)
70
- extended expiry of SUSE SLES11 key (bsc#1194845)
71
- added SUSE Contaner signing key in PEM format for use e.g. by cosign.
72
- SUSE security key replaced with 2022 edition (E-Mail usage only). (bsc#1196495)
73
74
-------------------------------------------------------------------
75
Mon Sep 21 08:30:03 UTC 2020 - Marcus Meissner <meissner@suse.com>
76
77
- suse build key extended (bsc#1176759)
78
gpg-pubkey-39db7c82-5847eb1f.asc -> gpg-pubkey-39db7c82-5f68629b.asc
79
80
81
-------------------------------------------------------------------
82
Thu Aug 13 09:32:26 UTC 2020 - Marcus Meissner <meissner@suse.com>
83
84
- actually the container key is different from the build signing
85
key. (PM-1845 bsc#1170347)
86
87
-------------------------------------------------------------------
88
Thu Apr 23 13:32:45 UTC 2020 - Marcus Meissner <meissner@suse.com>
89
90
- add a /usr/share/container-keys/ directory for GPG based Container
91
verification.
92
- Add the SUSE build key as "suse-container-key.asc". (PM-1845 bsc#1170347)
93
94
-------------------------------------------------------------------
95
Wed Mar 11 09:09:42 UTC 2020 - Marcus Meissner <meissner@suse.com>
96
97
- created a new security@suse.de communication key (bsc#1166334)
98
99
-------------------------------------------------------------------
100
Tue Nov 13 12:41:24 UTC 2018 - meissner@suse.com
101
102
- include ptf key in the key directory to avoid it being
103
stripped via %doc stripping. (bsc#1044232)
104
105
-------------------------------------------------------------------
106
Wed Mar 28 14:56:15 UTC 2018 - meissner@suse.com
107
108
- created a new security@suse.de communication key. (bsc#1082022)
109
- extended the PTF key and the SLE10 build@suse.de key. (bsc#1085512)
110
111
-------------------------------------------------------------------
112
Wed Dec 7 16:35:05 UTC 2016 - meissner@suse.com
113
114
- extend the build@suse.de product key. (bsc#1014151)
115
116
pub 2048R/39DB7C82 2013-01-31 [expires: 2020-12-06]
117
uid SuSE Package Signing Key <build@suse.de>
118
119
-------------------------------------------------------------------
120
Tue Nov 29 12:54:46 CET 2016 - ro@suse.de
121
122
- use dumpsigs script from openSUSE to merge code
123
124
-------------------------------------------------------------------
125
Thu Oct 2 12:45:05 UTC 2014 - meissner@suse.com
126
127
- renamed security_at_suse_de.asc to security_at_suse_de_old.asc
128
- security_at_suse_de.asc: new 4096 bit RSA key.
129
pub 4096R/317CD502 2014-10-02 SUSE Security Team <security@suse.de>
130
bnc#899509
131
132
-------------------------------------------------------------------
133
Fri Aug 29 08:28:03 UTC 2014 - meissner@suse.com
134
135
- Went to new method again.
136
- suse-build-key.gpg blob dropped
137
- ship seperate files
138
139
-------------------------------------------------------------------
140
Mon Feb 10 09:57:50 UTC 2014 - meissner@suse.com
141
142
- create suse-build-key.gpg during build.
143
- Remove old keys from keyring. (fate#314767)
144
Keys currently inside the RPM trusted keyring:
145
- pub 2048R/39DB7C82 SuSE Package Signing Key <build@suse.de>
146
- pub 2048R/50A3DD1C SuSE Package Signing Key (reserve key) <build@suse.de>
147
- Various keys are moved to the documentation area
148
(/usr/share/doc/packages/suse-build-key)
149
- build-at-suse-sle11.asc: the old SUSE Linux Enterprise 11 key.
150
if SUSE Linux Enterprise 11 packages need to be verified on
151
a SUSE Linux Enterprise 12 system.
152
- suse_ptf_key.asc: The suse ptf key. For verification of provided PTFs.
153
- security_at_suse_de.asc: Use only for email encryption and
154
verification purposes when contacting our security contact address
155
security@suse.de
156
157
-------------------------------------------------------------------
158
Mon Jan 13 15:01:24 UTC 2014 - meissner@suse.com
159
160
- reverted to contain the fullkeyring build SLE12 Alpha.
161
- also list the old sle11 build@suse.de key temporary
162
163
-------------------------------------------------------------------
164
Thu Jan 9 12:29:53 UTC 2014 - meissner@suse.com
165
166
- Merged over logic from openSUSE-build-key.
167
- Got rid of default importing into roots keyring.
168
- Removed some old keys.
169
- Clarify that security@suse.de is a email only key
170
- PTF key is supplied also as %doc, to not be default
171
imported.
172
- Keys currently inside:
173
- pub 2048R/39DB7C82 SuSE Package Signing Key <build@suse.de>
174
- pub 2048R/50A3DD1C SuSE Package Signing Key (reserve key) <build@suse.de>
175
- pub 1024D/B37B98A9 SUSE PTF Signing Key <support@suse.com>
176
- pub 2048R/3D25D3D9 SuSE Security Team <security@suse.de>
177
178
-------------------------------------------------------------------
179
Thu Jan 31 17:11:08 CET 2013 - ro@suse.de
180
181
- added future signing key for SLES (fate#314767) (bnc#801055)
182
using 2048 bit rsa key
183
184
-------------------------------------------------------------------
185
Mon Jan 14 01:55:36 CET 2013 - ro@suse.de
186
187
- added reserve key for SLES (fate#312896)
188
50A3DD1C SuSE Package Signing Key (reserve key) <build@suse.de>
189
valid until (2017-01-13)
190
191
-------------------------------------------------------------------
192
Sun Oct 21 23:03:01 CEST 2012 - ro@suse.de
193
194
- export keys to single files in /usr/lib/rpm/gnupg/keys
195
196
-------------------------------------------------------------------
197
Mon Dec 12 12:02:49 CET 2011 - ro@suse.de
198
199
- reduced key list. remaining keys:
200
307E3D54 SuSE Package Signing Key <build@suse.de>
201
3D25D3D9 SuSE Security Team <security@suse.de>
202
9C800ACA SuSE Package Signing Key <build@suse.de>
203
B37B98A9 SUSE PTF Signing Key <support@suse.com>
204
205
-------------------------------------------------------------------
206
Fri Jan 28 13:02:42 CET 2011 - ro@suse.de
207
208
- if we have to set $HOME, we also have to export the variable
209
(bnc#665912)
210
211
-------------------------------------------------------------------
212
Tue May 4 16:11:41 CEST 2010 - ro@suse.de
213
214
- updated keys: (bnc#600157,bnc#599167)
215
- 307E3D54 build@suse.de "SuSE Package Signing Key" (2014-05-03)
216
- 9C800ACA build@suse.de "SuSE Package Signing Key" (2014-05-03)
217
- B37B98A9 support@suse.com "SUSE PTF Signing Key" (2014-05-03)
218
- 7E2E3B05 novell-provo-build@novell.com "Novell Provo Build"
219
(2014-05-06)
220
- added keys:
221
- 1D061A62 support@novell.com
222
"build@novell.com (Novell Linux Products)" (2014-05-06)
223
224
-------------------------------------------------------------------
225
Fri Oct 31 14:28:18 CET 2008 - ro@suse.de
226
227
- added ptf key, expiring 2010-07-02
228
229
-------------------------------------------------------------------
230
Mon Jun 2 15:45:33 CEST 2008 - ro@suse.de
231
232
- update keys again: for collaboration with rpm, the current
233
self-signature needs to be the first signature found in a key
234
235
-------------------------------------------------------------------
236
Mon May 5 18:31:20 CEST 2008 - ro@suse.de
237
238
- updated keys
239
9C800ACA,8495160C,307E3D54: extend expiration by 2 years
240
until 2010-05-05
241
7E2E3B05: extend expiration by 2 years until 2010-05-24
242
243
-------------------------------------------------------------------
244
Mon Mar 19 16:49:05 CET 2007 - rguenther@suse.de
245
246
- merge suse-build-key keyring to roots gpg pubring
247
248
-------------------------------------------------------------------
249
Mon May 29 17:20:45 CEST 2006 - ro@suse.de
250
251
- added new official provo dsa autobuild key ID 7E2E3B05
252
253
-------------------------------------------------------------------
254
Fri May 19 14:02:59 CEST 2006 - ro@suse.de
255
256
- removed unused provo autobuild key
257
- added new official provo autobuild key ID A1912208
258
259
-------------------------------------------------------------------
260
Thu Apr 20 12:47:18 CEST 2006 - ro@suse.de
261
262
- add dumpsigs script here to have _one_ place for the script
263
264
-------------------------------------------------------------------
265
Fri Mar 31 16:53:02 CEST 2006 - ro@suse.de
266
267
- added build@suse.de rsa key ID 307E3D54
268
269
-------------------------------------------------------------------
270
Wed Jan 25 21:47:54 CET 2006 - mls@suse.de
271
272
- converted neededforbuild to BuildRequires
273
274
-------------------------------------------------------------------
275
Tue Oct 18 17:47:07 CEST 2005 - ro@suse.de
276
277
- use correct provo autobuild key
278
279
-------------------------------------------------------------------
280
Tue Oct 18 12:28:04 CEST 2005 - ro@suse.de
281
282
- added provo autobuild signing key (#128128)
283
- removed jds key
284
285
-------------------------------------------------------------------
286
Fri May 27 14:47:30 CEST 2005 - mls@suse.de
287
288
- added mktemp to PreReqs [#86177]
289
290
-------------------------------------------------------------------
291
Thu Apr 28 11:45:36 CEST 2005 - ro@suse.de
292
293
- added JDS public key (15c17deb)
294
295
-------------------------------------------------------------------
296
Tue Jan 25 18:10:26 CET 2005 - ro@suse.de
297
298
- added OES public key (0dfb3188)
299
300
-------------------------------------------------------------------
301
Tue Jun 22 12:28:07 CEST 2004 - ro@suse.de
302
303
- updated build key (expiration changed to 2008-06-21) (#42326)
304
305
-------------------------------------------------------------------
306
Tue Feb 24 12:19:49 CET 2004 - hmacht@suse.de
307
308
- building as non-root
309
310
-------------------------------------------------------------------
311
Tue Sep 9 18:51:02 CEST 2003 - ro@suse.de
312
313
- ignore return code from first gpg calls
314
315
-------------------------------------------------------------------
316
Tue Sep 9 18:23:07 MEST 2003 - draht@suse.de
317
318
- call gpg twice without any arguments for proper initialization
319
inside postinstall
320
321
-------------------------------------------------------------------
322
Tue Sep 9 17:43:55 MEST 2003 - draht@suse.de
323
324
- use temp file instead of pipe due to resource race between two
325
instances of gpg in %post.
326
327
-------------------------------------------------------------------
328
Thu Sep 5 04:56:32 CEST 2002 - draht@suse.de
329
330
- package now installs key from package-owned file into the rpm
331
pubring in %post to allow other key packages to add their keys.
332
333
-------------------------------------------------------------------
334
Tue Aug 20 10:46:52 CEST 2002 - mmj@suse.de
335
336
- Correct PreReq
337
338
-------------------------------------------------------------------
339
Fri Jul 26 09:50:14 CEST 2002 - kukuk@suse.de
340
341
- Change Provides from suse-build-key to build-key
342
343
-------------------------------------------------------------------
344
Thu Feb 21 00:10:52 MET 2002 - draht@suse.de
345
346
- directory permission problem: 644 -> 755.
347
348
-------------------------------------------------------------------
349
Mon Feb 18 12:16:34 CET 2002 - ro@suse.de
350
351
- moved to /usr/lib/rpm/gnupg/pubring.pgp
352
rpm needs a directory as gpg_path and will use pubring.gpg
353
in that directory
354
355
-------------------------------------------------------------------
356
Wed Feb 13 20:45:46 MET 2002 - draht@suse.de
357
358
- initial package. Contains
359
- pub 2048R/3D25D3D9 1999-03-06 SuSE Security Team <security@suse.de>
360
361
- pub 1024D/9C800ACA 2000-10-19 SuSE Package Signing Key <build@suse.de>
362
- sub 2048g/8495160C 2000-10-19 [expires: 2006-02-12]
363
364
365