[GH-ISSUE #3745] Public gpg key & Signature #2363

Closed
opened 2026-05-05 09:02:47 -06:00 by gitea-mirror · 5 comments
Owner

Originally created by @svc88 on GitHub (Nov 12, 2020).
Original GitHub issue: https://github.com/netblue30/firejail/issues/3745

Was wondering where is @netblue30 's public key so i can verify the files? or whoever is signing them? Havent been able to find it.

Also, is it possible to also sign the source files tar.gz as well ?

Originally created by @svc88 on GitHub (Nov 12, 2020). Original GitHub issue: https://github.com/netblue30/firejail/issues/3745 Was wondering where is @netblue30 's public key so i can verify the files? or whoever is signing them? Havent been able to find it. Also, is it possible to also sign the source files tar.gz as well ?
Author
Owner

@ghost commented on GitHub (Nov 12, 2020):

That's indeed a bit burried. You can find it on the project site under the 'Downloads' section: https://firejail.wordpress.com/download-2/.

Also, is it possible to also sign the source files tar.gz as well ?

Probably pinged the correct person on that one ;-)

<!-- gh-comment-id:726310577 --> @ghost commented on GitHub (Nov 12, 2020): That's indeed a bit burried. You can find it on the project site under the 'Downloads' section: https://firejail.wordpress.com/download-2/. > Also, is it possible to also sign the source files tar.gz as well ? Probably pinged the correct person on that one ;-)
Author
Owner

@rusty-snake commented on GitHub (Nov 12, 2020):

Also, is it possible to also sign the source files tar.gz as well ?

"Source Code (zip)" and "Source Code (tar.gz)" are auto-generated by :octocat: . However there is a signed tar.xz.

<!-- gh-comment-id:726319593 --> @rusty-snake commented on GitHub (Nov 12, 2020): > Also, is it possible to also sign the source files tar.gz as well ? "Source Code (zip)" and "Source Code (tar.gz)" are auto-generated by :octocat: . However there is a signed tar.xz.
Author
Owner

@svc88 commented on GitHub (Nov 12, 2020):

"Source Code (zip)" and "Source Code (tar.gz)" are auto-generated by :octocat: . However there is a signed tar.xz.

Ah ok, thank you

Also, would be better to show where to find the public key for other users on the Github page too.

<!-- gh-comment-id:726334029 --> @svc88 commented on GitHub (Nov 12, 2020): > "Source Code (zip)" and "Source Code (tar.gz)" are auto-generated by :octocat: . However there is a signed tar.xz. Ah ok, thank you Also, would be better to show where to find the public key for other users on the Github page too.
Author
Owner

@netblue30 commented on GitHub (Dec 7, 2020):

This guy has an interesting way of doing it: he grabs the public key form the MIT server and adds it to his keyring:

https://null-byte.wonderhowto.com/how-to/locking-down-linux-using-ubuntu-as-your-primary-os-part-3-application-hardening-sandboxing-0185710/

<!-- gh-comment-id:739994313 --> @netblue30 commented on GitHub (Dec 7, 2020): This guy has an interesting way of doing it: he grabs the public key form the MIT server and adds it to his keyring: https://null-byte.wonderhowto.com/how-to/locking-down-linux-using-ubuntu-as-your-primary-os-part-3-application-hardening-sandboxing-0185710/
Author
Owner

@rusty-snake commented on GitHub (Apr 6, 2021):

I'm closing here due to inactivity, please fell free to request to reopen if you have more questions.

<!-- gh-comment-id:814165002 --> @rusty-snake commented on GitHub (Apr 6, 2021): I'm closing here due to inactivity, please fell free to request to reopen if you have more questions.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: github-starred/firejail#2363
No description provided.