Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update openssl pgp keys and versions #719

Merged
merged 1 commit into from
Sep 5, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 3 additions & 4 deletions 3.12/alpine/Dockerfile

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

7 changes: 3 additions & 4 deletions 3.12/ubuntu/Dockerfile

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

7 changes: 3 additions & 4 deletions 3.13/alpine/Dockerfile

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

7 changes: 3 additions & 4 deletions 3.13/ubuntu/Dockerfile

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

7 changes: 3 additions & 4 deletions 4.0-rc/alpine/Dockerfile

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

7 changes: 3 additions & 4 deletions 4.0-rc/ubuntu/Dockerfile

Some generated files are not rendered by default. Learn more about how customized files appear on GitHub.

38 changes: 5 additions & 33 deletions Dockerfile-alpine.template
Original file line number Diff line number Diff line change
Expand Up @@ -22,42 +22,14 @@ ARG PGP_KEYSERVER=keyserver.ubuntu.com

ENV OPENSSL_VERSION {{ .openssl.version }}
ENV OPENSSL_SOURCE_SHA256="{{ .openssl.sha256 }}"
# https://www.openssl.org/community/otc.html
# https://www.openssl.org/source/
ENV OPENSSL_PGP_KEY_IDS="{{
[
# Dmitry Belyavsky

# Matt Caswell
"8657 ABB2 60F0 56B1 E519 0839 D9C4 D26D 0E60 4491",

# Paul Dale
"B7C1 C143 60F3 53A3 6862 E4D5 231C 84CD DCC6 9C45",

# Tim Hudson
"C1F3 3DD8 CE1D 4CC6 13AF 14DA 9195 C482 41FB F7DD",

# Hugo Landau
"95A9 908D DFA1 6830 BE9F B900 3D30 A3A9 FF13 60DC",

# Richard Levitte
"7953 AC1F BC3D C8B3 B292 393E D5E9 E43F 7DF9 EE8C",

# Shane Lontis

# Tomas Mraz
"A21F AB74 B008 8AA3 6115 2586 B8EF 1A6B A9DA 2D5C",

# Kurt Roeckx
"E5E5 2560 DD91 C556 DDBD A5D0 2064 C536 41C2 5E5D",

# Matthias St. Pierre

# Nicola Tuveri

# OpenSSL OMC key
# https://github.com/openssl/web/pull/415
"EFC0 A467 D613 CB83 C7ED 6D30 D894 E2CE 8B3D 79F5",
# "OpenSSL <[email protected]>"
# https://openssl-library.org/source/index.html
# "The current releases are signed by the OpenSSL key with fingerprint:"
# https://keys.openpgp.org/search?q=openssl%40openssl.org
"BA54 73A2 B058 7B07 FB27 CF2D 2160 94DF D0CB 81EF",

# hack for trailing comma above
empty
Expand Down
38 changes: 5 additions & 33 deletions Dockerfile-ubuntu.template
Original file line number Diff line number Diff line change
Expand Up @@ -25,42 +25,14 @@ ARG PGP_KEYSERVER=keyserver.ubuntu.com

ENV OPENSSL_VERSION {{ .openssl.version }}
ENV OPENSSL_SOURCE_SHA256="{{ .openssl.sha256 }}"
# https://www.openssl.org/community/otc.html
# https://www.openssl.org/source/
ENV OPENSSL_PGP_KEY_IDS="{{
[
# Dmitry Belyavsky

# Matt Caswell
"8657 ABB2 60F0 56B1 E519 0839 D9C4 D26D 0E60 4491",

# Paul Dale
"B7C1 C143 60F3 53A3 6862 E4D5 231C 84CD DCC6 9C45",

# Tim Hudson
"C1F3 3DD8 CE1D 4CC6 13AF 14DA 9195 C482 41FB F7DD",

# Hugo Landau
"95A9 908D DFA1 6830 BE9F B900 3D30 A3A9 FF13 60DC",

# Richard Levitte
"7953 AC1F BC3D C8B3 B292 393E D5E9 E43F 7DF9 EE8C",

# Shane Lontis

# Tomas Mraz
"A21F AB74 B008 8AA3 6115 2586 B8EF 1A6B A9DA 2D5C",

# Kurt Roeckx
"E5E5 2560 DD91 C556 DDBD A5D0 2064 C536 41C2 5E5D",

# Matthias St. Pierre

# Nicola Tuveri

# OpenSSL OMC key
# https://github.com/openssl/web/pull/415
"EFC0 A467 D613 CB83 C7ED 6D30 D894 E2CE 8B3D 79F5",
# "OpenSSL <[email protected]>"
# https://openssl-library.org/source/index.html
# "The current releases are signed by the OpenSSL key with fingerprint:"
# https://keys.openpgp.org/search?q=openssl%40openssl.org
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Since we only appear to use PGP_KEYSERVER for OpenSSL, perhaps we should just switch to the superior keys.openpgp.org service explicitly? 👀

"BA54 73A2 B058 7B07 FB27 CF2D 2160 94DF D0CB 81EF",

# hack for trailing comma above
empty
Expand Down
12 changes: 6 additions & 6 deletions versions.json
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,8 @@
"version": "3.20"
},
"openssl": {
"sha256": "5d2be4036b478ef3cb0a854ca9b353072c3a0e26d8a56f8f0ab9fb6ed32d38d7",
"version": "3.1.6"
"sha256": "053a31fa80cf4aebe1068c987d2ef1e44ce418881427c4464751ae800c31d06c",
"version": "3.1.7"
},
"otp": {
"sha256": "00c2619648e05a25b39035ea51b65fc79c998e55f178cccc6c1b920f3f10dfba",
Expand All @@ -22,8 +22,8 @@
"version": "3.20"
},
"openssl": {
"sha256": "5d2be4036b478ef3cb0a854ca9b353072c3a0e26d8a56f8f0ab9fb6ed32d38d7",
"version": "3.1.6"
"sha256": "053a31fa80cf4aebe1068c987d2ef1e44ce418881427c4464751ae800c31d06c",
"version": "3.1.7"
},
"otp": {
"sha256": "e49708cf1f602863e394869af48df4abcb39e3633b96cb4babde3ee7aa724872",
Expand All @@ -40,8 +40,8 @@
"version": "3.20"
},
"openssl": {
"sha256": "777cd596284c883375a2a7a11bf5d2786fc5413255efab20c50d6ffe6d020b7e",
"version": "3.3.1"
"sha256": "2e8a40b01979afe8be0bbfb3de5dc1c6709fedb46d6c89c10da114ab5fc3d281",
"version": "3.3.2"
},
"otp": {
"sha256": "e49708cf1f602863e394869af48df4abcb39e3633b96cb4babde3ee7aa724872",
Expand Down
Loading