Issue 126352 - Location of KEYS file
Summary: Location of KEYS file
Status: CLOSED FIXED
Alias: None
Product: Infrastructure
Classification: Infrastructure
Component: Website general issues (show other issues)
Version: current
Hardware: All All
: P5 (lowest) Normal (vote)
Target Milestone: ---
Assignee: Marcus
QA Contact:
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2015-06-03 21:15 UTC by sebb
Modified: 2019-09-23 18:09 UTC (History)
1 user (show)

See Also:
Issue Type: DEFECT
Latest Confirmation in: ---
Developer Difficulty: ---


Attachments

Note You need to log in before you can comment on or make changes to this issue.
Description sebb 2015-06-03 21:15:28 UTC
The download page

http://www.openoffice.org/download/index.html

contains a link to the KEYS file as follows:

http://people.apache.org/keys/group/openoffice.asc

However the KEYS file should always be linked from the ASF mirror master, i.e. under

http://www.apache.org/dist/openoffice/

The KEYS file in this location must contain all keys that were ever used to sign ASF releases. This is so that users can still check signatures for archived releases. [Entries should only ever be added to that file].

The files under http://people.apache.org/keys/ may not always contain every such key, as they rely on RMs maintaining the full set of keys in LDAP, and on an RM remaining a member of the PMC.

Note that the KEYS file source can be maintained in SVN, but it should be published via the ASF dist mirror URL.
Comment 1 Kay 2015-06-04 21:47:57 UTC
Thanks. I know at one time the Linux builds were signed separately from the other builds, but I'm not sure why this is linked this way now. We will fix.
Comment 2 Marcus 2015-06-06 21:31:50 UTC
I've committed the change but SVN is still not fully back from restoring. I'll wait until Sunday evening. Otherwise will ask @infra for info/help.
Comment 3 Marcus 2015-06-11 11:27:27 UTC
After the SVN trouble here the commit message from the log:

$ svn log download.js | less

r1683888 | marcus | 2015-06-06 08:57:28 +0200 (Sat, 06 Jun 2015) | 1 line

#i126352# Fixed wrong URL for the KEYS file, should refer to the DIST server and not 'people.apache.org'
Comment 4 sebb 2019-09-23 10:33:59 UTC
The page:

https://openoffice.apache.org/downloads.html
currently has two KEYS links pointing to:
https://people.apache.org/keys/group/openoffice.asc

This is wrong; the KEYS file link must point to
https://www.apache.org/dist/openoffice/KEYS
Comment 5 Marcus 2019-09-23 18:09:02 UTC
Fixed with SVN rev. 1867387.