File suse-build-key.changes of Package suse-build-key (Revision 882d5e807cc8da86ce1bcec0be69ad1f)
Currently displaying revision 882d5e807cc8da86ce1bcec0be69ad1f , Show latest
378
1
-------------------------------------------------------------------
2
Fri Jul 12 12:33:23 UTC 2024 - Marcus Meissner <meissner@suse.com>
3
4
- added missing ; in shell script (bsc#1227681)
5
6
-------------------------------------------------------------------
7
Mon Jul 8 14:31:48 UTC 2024 - Marcus Meissner <meissner@suse.com>
8
9
- Added new keys of the SLE Micro 6.0 / SLES 16 series, and auto import
10
them. (bsc#1227429)
11
gpg-pubkey-09d9ea69-645b99ce.asc: Main SLE Micro 6/SLES 16 key
12
gpg-pubkey-73f03759-626bd414.asc: Backup SLE Micro 6/SLES 16 key.
13
14
-------------------------------------------------------------------
15
Fri Feb 9 12:34:40 UTC 2024 - Marcus Meissner <meissner@suse.com>
16
17
- Switch container key to be default RSA 4096bit. (jsc#PED-2777)
18
19
-------------------------------------------------------------------
20
Sun Jan 28 15:24:55 UTC 2024 - Marcus Meissner <meissner@suse.com>
21
22
- run rpm commands in import script only when libzypp is not
23
active. bsc#1219189 bsc#1219123
24
25
-------------------------------------------------------------------
26
Sun Jan 28 15:24:55 UTC 2024 - Marcus Meissner <meissner@suse.com>
27
28
- run import script also in %posttrans section, but only when
29
libzypp is not active. bsc#1219189 bsc#1219123
30
31
-------------------------------------------------------------------
32
Thu Nov 16 12:50:14 UTC 2023 - Marcus Meissner <meissner@suse.com>
33
34
- replace libzypp-post-script based installation with a systemd timer
35
and service.
36
- suse-build-key-import.service
37
- suse-build-key-import.timer
38
39
-------------------------------------------------------------------
40
Fri Sep 8 09:41:33 UTC 2023 - Marcus Meissner <meissner@suse.com>
41
42
- add and run a import-suse-build-key scripts, this will be ran
43
after installation with libzypp based installers. (jsc#PED-2777)
44
45
-------------------------------------------------------------------
46
Tue Feb 7 10:41:12 UTC 2023 - Marcus Meissner <meissner@suse.com>
47
48
- Establish multiple new 4096 RSA keys that we will switch
49
to mid of 2023. (jsc#PED-2777)
50
- gpg-pubkey-3fa1d6ce-63c9481c.asc: new 4096 RSA signing key for SLE (RPM+repos).
51
- gpg-pubkey-d588dc46-63c939db.asc: new 4096 RSA reserver key for SLE (RPM+repos).
52
- suse_ptf_key_4096.asc: new 4096 RSA signing key for PTF RPMs.
53
- build-container-8fd6c337-63c94b45.asc/build-container-8fd6c337-63c94b45.pem:
54
new RSA 4096 key for the SUSE registry registry.suse.com, installed as
55
suse-container-key-2023.pem and suse-container-key-2023.asc
56
- suse_ptf_containerkey_2023.asc suse_ptf_containerkey_2023.pem:
57
New PTF container signing key for registry.suse.com/ptf/ space.
58
59
-------------------------------------------------------------------
60
Tue Oct 25 12:19:09 UTC 2022 - Marcus Meissner <meissner@suse.com>
61
62
- added /usr/share/pki/containers directory for container pem keys
63
(cosign/sigstore style), put our PEM key there too (bsc#1204706)
64
65
-------------------------------------------------------------------
66
Thu Apr 21 12:47:26 UTC 2022 - Marcus Meissner <meissner@suse.com>
67
68
- still ship the old ptf key (was not added to documentation by mistake).
69
(bsc#1198504)
70
71
-------------------------------------------------------------------
72
Thu Mar 24 09:07:52 UTC 2022 - Marcus Meissner <meissner@suse.com>
73
74
- No longer install 1024bit keys by default. (bsc#1197293)
75
- SLE11 key moved to documentation
76
- old PTF (pre March 2022) moved to documentation only
77
78
-------------------------------------------------------------------
79
Thu Feb 17 12:28:49 UTC 2022 - Marcus Meissner <meissner@suse.com>
80
81
- extended expiry of SUSE PTF key, move it to suse_ptf_key_old.asc
82
- added new SUSE PTF key with RSA2048 bit as suse_ptf_key.asc (bsc#1196494)
83
- extended expiry of SUSE SLES11 key (bsc#1194845)
84
- added SUSE Contaner signing key in PEM format for use e.g. by cosign.
85
- SUSE security key replaced with 2022 edition (E-Mail usage only). (bsc#1196495)
86
87
-------------------------------------------------------------------
88
Mon Sep 21 08:30:03 UTC 2020 - Marcus Meissner <meissner@suse.com>
89
90
- suse build key extended (bsc#1176759)
91
gpg-pubkey-39db7c82-5847eb1f.asc -> gpg-pubkey-39db7c82-5f68629b.asc
92
93
94
-------------------------------------------------------------------
95
Thu Aug 13 09:32:26 UTC 2020 - Marcus Meissner <meissner@suse.com>
96
97
- actually the container key is different from the build signing
98
key. (PM-1845 bsc#1170347)
99
100
-------------------------------------------------------------------
101
Thu Apr 23 13:32:45 UTC 2020 - Marcus Meissner <meissner@suse.com>
102
103
- add a /usr/share/container-keys/ directory for GPG based Container
104
verification.
105
- Add the SUSE build key as "suse-container-key.asc". (PM-1845 bsc#1170347)
106
107
-------------------------------------------------------------------
108
Wed Mar 11 09:09:42 UTC 2020 - Marcus Meissner <meissner@suse.com>
109
110
- created a new security@suse.de communication key (bsc#1166334)
111
112
-------------------------------------------------------------------
113
Tue Nov 13 12:41:24 UTC 2018 - meissner@suse.com
114
115
- include ptf key in the key directory to avoid it being
116
stripped via %doc stripping. (bsc#1044232)
117
118
-------------------------------------------------------------------
119
Wed Mar 28 14:56:15 UTC 2018 - meissner@suse.com
120
121
- created a new security@suse.de communication key. (bsc#1082022)
122
- extended the PTF key and the SLE10 build@suse.de key. (bsc#1085512)
123
124
-------------------------------------------------------------------
125
Wed Dec 7 16:35:05 UTC 2016 - meissner@suse.com
126
127
- extend the build@suse.de product key. (bsc#1014151)
128
129
pub 2048R/39DB7C82 2013-01-31 [expires: 2020-12-06]
130
uid SuSE Package Signing Key <build@suse.de>
131
132
-------------------------------------------------------------------
133
Tue Nov 29 12:54:46 CET 2016 - ro@suse.de
134
135
- use dumpsigs script from openSUSE to merge code
136
137
-------------------------------------------------------------------
138
Thu Oct 2 12:45:05 UTC 2014 - meissner@suse.com
139
140
- renamed security_at_suse_de.asc to security_at_suse_de_old.asc
141
- security_at_suse_de.asc: new 4096 bit RSA key.
142
pub 4096R/317CD502 2014-10-02 SUSE Security Team <security@suse.de>
143
bnc#899509
144
145
-------------------------------------------------------------------
146
Fri Aug 29 08:28:03 UTC 2014 - meissner@suse.com
147
148
- Went to new method again.
149
- suse-build-key.gpg blob dropped
150
- ship seperate files
151
152
-------------------------------------------------------------------
153
Mon Feb 10 09:57:50 UTC 2014 - meissner@suse.com
154
155
- create suse-build-key.gpg during build.
156
- Remove old keys from keyring. (fate#314767)
157
Keys currently inside the RPM trusted keyring:
158
- pub 2048R/39DB7C82 SuSE Package Signing Key <build@suse.de>
159
- pub 2048R/50A3DD1C SuSE Package Signing Key (reserve key) <build@suse.de>
160
- Various keys are moved to the documentation area
161
(/usr/share/doc/packages/suse-build-key)
162
- build-at-suse-sle11.asc: the old SUSE Linux Enterprise 11 key.
163
if SUSE Linux Enterprise 11 packages need to be verified on
164
a SUSE Linux Enterprise 12 system.
165
- suse_ptf_key.asc: The suse ptf key. For verification of provided PTFs.
166
- security_at_suse_de.asc: Use only for email encryption and
167
verification purposes when contacting our security contact address
168
security@suse.de
169
170
-------------------------------------------------------------------
171
Mon Jan 13 15:01:24 UTC 2014 - meissner@suse.com
172
173
- reverted to contain the fullkeyring build SLE12 Alpha.
174
- also list the old sle11 build@suse.de key temporary
175
176
-------------------------------------------------------------------
177
Thu Jan 9 12:29:53 UTC 2014 - meissner@suse.com
178
179
- Merged over logic from openSUSE-build-key.
180
- Got rid of default importing into roots keyring.
181
- Removed some old keys.
182
- Clarify that security@suse.de is a email only key
183
- PTF key is supplied also as %doc, to not be default
184
imported.
185
- Keys currently inside:
186
- pub 2048R/39DB7C82 SuSE Package Signing Key <build@suse.de>
187
- pub 2048R/50A3DD1C SuSE Package Signing Key (reserve key) <build@suse.de>
188
- pub 1024D/B37B98A9 SUSE PTF Signing Key <support@suse.com>
189
- pub 2048R/3D25D3D9 SuSE Security Team <security@suse.de>
190
191
-------------------------------------------------------------------
192
Thu Jan 31 17:11:08 CET 2013 - ro@suse.de
193
194
- added future signing key for SLES (fate#314767) (bnc#801055)
195
using 2048 bit rsa key
196
197
-------------------------------------------------------------------
198
Mon Jan 14 01:55:36 CET 2013 - ro@suse.de
199
200
- added reserve key for SLES (fate#312896)
201
50A3DD1C SuSE Package Signing Key (reserve key) <build@suse.de>
202
valid until (2017-01-13)
203
204
-------------------------------------------------------------------
205
Sun Oct 21 23:03:01 CEST 2012 - ro@suse.de
206
207
- export keys to single files in /usr/lib/rpm/gnupg/keys
208
209
-------------------------------------------------------------------
210
Mon Dec 12 12:02:49 CET 2011 - ro@suse.de
211
212
- reduced key list. remaining keys:
213
307E3D54 SuSE Package Signing Key <build@suse.de>
214
3D25D3D9 SuSE Security Team <security@suse.de>
215
9C800ACA SuSE Package Signing Key <build@suse.de>
216
B37B98A9 SUSE PTF Signing Key <support@suse.com>
217
218
-------------------------------------------------------------------
219
Fri Jan 28 13:02:42 CET 2011 - ro@suse.de
220
221
- if we have to set $HOME, we also have to export the variable
222
(bnc#665912)
223
224
-------------------------------------------------------------------
225
Tue May 4 16:11:41 CEST 2010 - ro@suse.de
226
227
- updated keys: (bnc#600157,bnc#599167)
228
- 307E3D54 build@suse.de "SuSE Package Signing Key" (2014-05-03)
229
- 9C800ACA build@suse.de "SuSE Package Signing Key" (2014-05-03)
230
- B37B98A9 support@suse.com "SUSE PTF Signing Key" (2014-05-03)
231
- 7E2E3B05 novell-provo-build@novell.com "Novell Provo Build"
232
(2014-05-06)
233
- added keys:
234
- 1D061A62 support@novell.com
235
"build@novell.com (Novell Linux Products)" (2014-05-06)
236
237
-------------------------------------------------------------------
238
Fri Oct 31 14:28:18 CET 2008 - ro@suse.de
239
240
- added ptf key, expiring 2010-07-02
241
242
-------------------------------------------------------------------
243
Mon Jun 2 15:45:33 CEST 2008 - ro@suse.de
244
245
- update keys again: for collaboration with rpm, the current
246
self-signature needs to be the first signature found in a key
247
248
-------------------------------------------------------------------
249
Mon May 5 18:31:20 CEST 2008 - ro@suse.de
250
251
- updated keys
252
9C800ACA,8495160C,307E3D54: extend expiration by 2 years
253
until 2010-05-05
254
7E2E3B05: extend expiration by 2 years until 2010-05-24
255
256
-------------------------------------------------------------------
257
Mon Mar 19 16:49:05 CET 2007 - rguenther@suse.de
258
259
- merge suse-build-key keyring to roots gpg pubring
260
261
-------------------------------------------------------------------
262
Mon May 29 17:20:45 CEST 2006 - ro@suse.de
263
264
- added new official provo dsa autobuild key ID 7E2E3B05
265
266
-------------------------------------------------------------------
267
Fri May 19 14:02:59 CEST 2006 - ro@suse.de
268
269
- removed unused provo autobuild key
270
- added new official provo autobuild key ID A1912208
271
272
-------------------------------------------------------------------
273
Thu Apr 20 12:47:18 CEST 2006 - ro@suse.de
274
275
- add dumpsigs script here to have _one_ place for the script
276
277
-------------------------------------------------------------------
278
Fri Mar 31 16:53:02 CEST 2006 - ro@suse.de
279
280
- added build@suse.de rsa key ID 307E3D54
281
282
-------------------------------------------------------------------
283
Wed Jan 25 21:47:54 CET 2006 - mls@suse.de
284
285
- converted neededforbuild to BuildRequires
286
287
-------------------------------------------------------------------
288
Tue Oct 18 17:47:07 CEST 2005 - ro@suse.de
289
290
- use correct provo autobuild key
291
292
-------------------------------------------------------------------
293
Tue Oct 18 12:28:04 CEST 2005 - ro@suse.de
294
295
- added provo autobuild signing key (#128128)
296
- removed jds key
297
298
-------------------------------------------------------------------
299
Fri May 27 14:47:30 CEST 2005 - mls@suse.de
300
301
- added mktemp to PreReqs [#86177]
302
303
-------------------------------------------------------------------
304
Thu Apr 28 11:45:36 CEST 2005 - ro@suse.de
305
306
- added JDS public key (15c17deb)
307
308
-------------------------------------------------------------------
309
Tue Jan 25 18:10:26 CET 2005 - ro@suse.de
310
311
- added OES public key (0dfb3188)
312
313
-------------------------------------------------------------------
314
Tue Jun 22 12:28:07 CEST 2004 - ro@suse.de
315
316
- updated build key (expiration changed to 2008-06-21) (#42326)
317
318
-------------------------------------------------------------------
319
Tue Feb 24 12:19:49 CET 2004 - hmacht@suse.de
320
321
- building as non-root
322
323
-------------------------------------------------------------------
324
Tue Sep 9 18:51:02 CEST 2003 - ro@suse.de
325
326
- ignore return code from first gpg calls
327
328
-------------------------------------------------------------------
329
Tue Sep 9 18:23:07 MEST 2003 - draht@suse.de
330
331
- call gpg twice without any arguments for proper initialization
332
inside postinstall
333
334
-------------------------------------------------------------------
335
Tue Sep 9 17:43:55 MEST 2003 - draht@suse.de
336
337
- use temp file instead of pipe due to resource race between two
338
instances of gpg in %post.
339
340
-------------------------------------------------------------------
341
Thu Sep 5 04:56:32 CEST 2002 - draht@suse.de
342
343
- package now installs key from package-owned file into the rpm
344
pubring in %post to allow other key packages to add their keys.
345
346
-------------------------------------------------------------------
347
Tue Aug 20 10:46:52 CEST 2002 - mmj@suse.de
348
349
- Correct PreReq
350
351
-------------------------------------------------------------------
352
Fri Jul 26 09:50:14 CEST 2002 - kukuk@suse.de
353
354
- Change Provides from suse-build-key to build-key
355
356
-------------------------------------------------------------------
357
Thu Feb 21 00:10:52 MET 2002 - draht@suse.de
358
359
- directory permission problem: 644 -> 755.
360
361
-------------------------------------------------------------------
362
Mon Feb 18 12:16:34 CET 2002 - ro@suse.de
363
364
- moved to /usr/lib/rpm/gnupg/pubring.pgp
365
rpm needs a directory as gpg_path and will use pubring.gpg
366
in that directory
367
368
-------------------------------------------------------------------
369
Wed Feb 13 20:45:46 MET 2002 - draht@suse.de
370
371
- initial package. Contains
372
- pub 2048R/3D25D3D9 1999-03-06 SuSE Security Team <security@suse.de>
373
374
- pub 1024D/9C800ACA 2000-10-19 SuSE Package Signing Key <build@suse.de>
375
- sub 2048g/8495160C 2000-10-19 [expires: 2006-02-12]
376
377
378