Add David's key
distribution packagers need to know who is authorized to sign tarballs because tor is quite important software to users.
With the release of 0.4.6.10, the signing changed, so please update gpg fingerprints on support.torproject.org
distribution packagers need to know who is authorized to sign tarballs because tor is quite important software to users.
With the release of 0.4.6.10, the signing changed, so please update gpg fingerprints on support.torproject.org
(https://support.torproject.org/little-t-tor/verify-little-t-tor/ is the page they mentioned on irc)
added Documentation label
As a point of reference, the tor.git README.md
has been updated with who and which keys can sign the tarball:
https://gitlab.torproject.org/tpo/core/tor/-/blob/main/README.md#keys-that-can-sign-a-release
We've changed how releases are done recently and I'm behind on things but we'll soon do a blog post about what/how things have changed.
In the meantime, the README can be used and we should update:
https://support.torproject.org/little-t-tor/verify-little-t-tor/
closed