Rolling Release Package Signing Keys
Packages provided by Nevis through the Nevis Portal download section are signed in order to allow signature checks.
The keys and signatures are used by:
- Docker images
- RPMs
- Maven artefacts
- Raw archives
Public GPG Key
The public GPG key for the Nevis rolling versions is:
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v2
mQENBF5rcqkBCADFahDK+l++oXpiuTXgsGjl0uYh1fJdNlEClifyscqvO7C7fNhs
Cu99wrMktqpiZH2iuQwgE0CMaoPLNREemDyj5p+hF7QKED0CzfDwd72UmNxaWy9l
3rj8NAFD5MqFXUb075GYtXtYvNBO5foa3diFKr1cezV2ctW64Gp9eZgIMHid2fVE
ge/c4fqF7+vK5MX1sW43xtibTeuKlB+suWE2ryQGCHUedXm35GmIYQsdM6Itc/zY
qLXpLyyI9Q6SwAEbp1JbgRXNMPGiKlCnRgvQJjxT/ZECS/vr9KKkyMedjCsla5RA
TpBR56KeyZHskbCSAEppvUQkOZ6vSJefLmklABEBAAG0QkNsb3Vkc21pdGggUGFj
a2FnZSAobmV2aXNzZWN1cml0eS9yb2xsaW5nKSA8c3VwcG9ydEBjbG91ZHNtaXRo
LmlvPokBNwQTAQgAIQUCXmtyqQIbLwULCQgHAwUVCgkICwUWAgMBAAIeAQIXgAAK
CRA/ZJ9fuoAR2B/5CACMOZOeIrapzdvscC4vjbx2F2f1GnOv6S8PrkiDtGSOZ25U
LPQhlXMGKWYpXiml+Yy+a8wgZdbG6zxbjaEbXyIBQwGk2FuNdGkgm847OEnfqE4O
2F2JXl2xRW01xyc97C1JDlI1ji2wCzOyagFgtply4b/653hDgdOhppbSxgMisMqp
BsmSL1HVW2I1o3z2oyuk77MeouOycZQ5xWeIsF0O4iR5WP/91xJimqcQceVfDf3L
DAOzefsiHmlPTkAdpUWqFXAB113OpToy5nVzfwu/M6QDWfLL9b3xsrp4XKxJpuwF
6P0S4PRJVBh8Rek02rqrWH/gkatLxhQhwDTvwQmc
=SLAN
-----END PGP PUBLIC KEY BLOCK-----
It has the following long (20 bytes) and short (8 bytes) fingerprints:
13AEC188AB9AE2F933A2DB703F649F5FBA8011D8
3F649F5FBA8011D8
Public RSA Key
The public RSA key for the Nevis rolling versions is:
-----BEGIN PUBLIC KEY-----
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA1SjWlN33y/Iy2m44aqyF
Vmy2R+mtGFwYQVO3GYk3yfUtYe+eexqCQtlP0YTU2aH2sxyVAgLeXopf6oWxPErA
VVID435cMYbHqi7tiCnVjJmiFXwrJrBGxmIILE4Py778wRRx5p9A6HTfr5QSIoOq
MQbZ16tQFHsw/pW9wXfhY+EOuaYK0Ee6YheemlntwZA/+XInaRDELCt6BDy2jiGN
2QMn6rCJR3DGSEtAHB3Gl6Y7q3/nTmPBBpiPGrLLc8gWYFLuX2YsZicvw8X86kyI
iF+JOt3mgY+LXUIuqMrhFiVukuuPqXl6+4HWJXxpwEl7a3nkDP2wriEct+RR9Tjk
8QIDAQAB
-----END PUBLIC KEY-----
It has the following long (16 bytes) and short (8 bytes) fingerprints:
C1148A8A834BC69DE3C6362875D6AD33
E3C6362875D6AD33
Key Rotation
There is no key rotation for a given Nevis release stream, the keys are perpetual. However, every release stream of Nevis components has its own signature keys.