Skip to content

Conversation

@kayiwa
Copy link
Member

@kayiwa kayiwa commented Dec 2, 2025

the phusion folks have switched to new signing infrastructure. Rather than use onesie twosies we bolt on the new key to the passenger role

closes https://gitlab.lib.princeton.edu/ops/team-handbook/-/issues/204

kayiwa and others added 2 commits December 2, 2025 13:12
the phusion folks have switched to new signing infrastructure. Rather
than use onesie twosies we bolt on the new key to the passenger role

Co-authored-by: Vickie Karasic <[email protected]>
@kayiwa
Copy link
Member Author

kayiwa commented Dec 2, 2025

verified by running this branch on a sandbox machine

pulsys@sandbox-dp1285:~$ curl https://phusion-public.s3.us-east-1.amazonaws.com/message.txt > message.txt
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed
100    20  100    20    0     0     98      0 --:--:-- --:--:-- --:--:--    99
pulsys@sandbox-dp1285:~$ curl https://phusion-public.s3.us-east-1.amazonaws.com/message.txt.sig > message.txt.sig
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed
100   566  100   566    0     0   2781      0 --:--:-- --:--:-- --:--:--  2788
pulsys@sandbox-dp1285:~$ gpg --no-default-keyring --keyring /etc/apt/trusted.gpg.d/phusion_new.gpg --verify message.txt.sig
gpg: assuming signed data in 'message.txt'
gpg: Signature made Tue 07 Oct 2025 02:51:18 PM UTC
gpg:                using RSA key C6F448ED4BC80A4E95257250D870AB033FB45BD1
gpg: directory '/home/pulsys/.gnupg' created
gpg: /home/pulsys/.gnupg/trustdb.gpg: trustdb created
gpg: Good signature from "Phusion Automated Software Signing (Used by automated tools to sign software packages, SHA256 signature) <[email protected]>" [unknown]
gpg: WARNING: This key is not certified with a trusted signature!
gpg:          There is no indication that the signature belongs to the owner.
Primary key fingerprint: C6F4 48ED 4BC8 0A4E 9525  7250 D870 AB03 3FB4 5BD1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants