]> xenbits.xensource.com Git - libvirt.git/commitdiff
docs: Mention GPG key used for signing releases
authorJiri Denemark <jdenemar@redhat.com>
Wed, 14 Oct 2020 11:24:29 +0000 (13:24 +0200)
committerJiri Denemark <jdenemar@redhat.com>
Wed, 14 Oct 2020 15:33:27 +0000 (17:33 +0200)
Signed-off-by: Jiri Denemark <jdenemar@redhat.com>
Reviewed-by: Erik Skultety <eskultet@redhat.com>
docs/downloads.html.in

index 43366b36943a2610b4c261f79630928a6b656cd1..aa0bb23d4594b6d868b6e358633d2da8f1090535 100644 (file)
       <li><a href="https://libvirt.org/sources/">libvirt.org HTTPS server</a></li>
     </ul>
 
+    <h2><a id="keys">Signing keys</a></h2>
+
+    <p>
+      Source RPM packages and tarballs for libvirt and libvirt-python published
+      on this project site are signed with a GPG signature. You should always
+      verify the package signature before using the source to compile binary
+      packages. The following key is currently used to generate the GPG
+      signatures:
+    </p>
+    <pre>
+pub  4096R/10084C9C 2020-07-20 Jiří Denemark &lt;jdenemar@redhat.com&gt;
+Fingerprint=453B 6531 0595 5628 5547  1199 CA68 BE80 1008 4C9C
+</pre>
+
     <h2><a id="schedule">Primary release schedule</a></h2>
 
     <p>