|
[[!meta date="Mon, 16 Mar 2015 12:34:56 +0000"]]
|
[[!meta date="Mon, 16 Mar 2015 12:34:56 +0000"]]
|
|
[[!pagetemplate template="news.tmpl"]]
|
[[!pagetemplate template="news.tmpl"]]
|
|
[[!meta title="Transition to a new OpenPGP signing key"]]
|
|
|
[[!tag announce]]
|
[[!tag announce]]
|
|
Tails is transitioning to a new OpenPGP signing key.
|
|
|
The signing key is the key that we use to:
|
|
|
Sign our official ISO images.
|
|
|
Certify the other [[OpenPGP keys|doc/about/openpgp_keys]] used by the project.
|
|
|
<div class="note">
|
<div class="note">
|
|
<p>The previous signing key is safe and, to the best of our knowledge, it has not been compromised.</p>
|
|
|
<p>We are doing this change to improve our security practices when manipulating such a critical piece of data.</p>
|
|
|
</div>
|
</div>
|
|
<div class="tip">
|
<div class="tip">
|
|
<ul> <li>The old key can still be used to verify Tails 1.3 ISO images.</li> <li>The new key will be used to sign ISO images starting from Tails 1.3.1.</li> </ul>
|
|
|
Import and verify the new signing key
|
|
|
Click on the following button to download and import the new signing key:
|
|
|
<a class="download-key" href="https://tails.net/tails-signing.key">new Tails signing key</a>
|
|
|
The new signing key is itself signed by the old signing key. So you can transitively trust this new key if you had trusted the old signing key.
|
|
|
To verify that the new key is correctly signed by the old key, you can execute the following command:
|
|
|
gpg --check-sigs A490D0F4D311A4153E2BB7CADBB802B258ACD84F
|
|