Difference between revisions of "Release Channels and Signing Keys"

From F-Droid
Jump to: navigation, search
(document Privileged Extension git tag signature)
(moved to https://f-droid.org/docs/Release_Channels_and_Signing_Keys)
 
Line 1: Line 1:
 
+
moved to https://f-droid.org/docs/Release_Channels_and_Signing_Keys
== FDroid app for Android ==
+
 
+
* git repo: https://gitlab.com/fdroid/fdroidclient
+
** git tags signed by "Daniel Martí <mvdan@mvdan.cc>" aka "Daniel Martí <mvdan@fsfe.org>" with fingerprint: <br /><code>A9DA 13CD F7A1 4ACD D3DE  E530 F4CA FFDB 4348 041C</code>
+
** release command: <code>git tag -s</code>
+
* official binary releases: https://f-droid.org/repository/browse/?fdfilter=f-droid&fdid=org.fdroid.fdroid
+
** GPG signing key: "F-Droid <admin@f-droid.org>" <br/>Primary key fingerprint: <code>37D2 C987 89D8 3119 4839  4E3E 41E7 044E 1DBA 2E89</code><br />Subkey fingerprint: <code>802A 9799 0161 1234 6E1F  EFF4 7A02 9E54 DD5D CE7A</code>
+
** APK signing key:
+
<pre>
+
Owner: CN=Ciaran Gultnieks, OU=Unknown, O=Unknown, L=Wetherby, ST=Unknown, C=UK
+
Issuer: CN=Ciaran Gultnieks, OU=Unknown, O=Unknown, L=Wetherby, ST=Unknown, C=UK
+
Serial number: 4c49cd00
+
Valid from: Fri Jul 23 13:10:24 EDT 2010 until: Tue Dec 08 12:10:24 EST 2037
+
Certificate fingerprints:
+
  MD5:  17:C5:5C:62:80:56:E1:93:E9:56:44:E9:89:79:27:86
+
  SHA1: 05:F2:E6:59:28:08:89:81:B3:17:FC:9A:6D:BF:E0:4B:0F:A1:3B:4E
+
  SHA256: 43:23:8D:51:2C:1E:5E:B2:D6:56:9F:4A:3A:FB:F5:52:34:18:B8:2E:0A:3E:D1:55:27:70:AB:B9:A9:C9:CC:AB
+
</pre>
+
 
+
And here is the whole certificate:
+
 
+
<pre>
+
-----BEGIN PUBLIC KEY-----
+
MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAltB15HwBTngiyJ/Wf3ld
+
IyA+KohD9Tuk5rG/Xy/Q4iWTgmfPyuf79P5ZY0avuvQHD9uR9m+83yNIo9kkMFAo
+
JPgFF7FW+rAICb3I5jG/qa/ULZBFq1/W0o2eFAr8EwCRexm3xsTfSklM8ffLSmPI
+
DXNCZdc1r55PCUVfQnqmWlNWP4ezNsosGdJE/LumF7oLGeVu00r+CyU6uR4v2xJx
+
8bnjwyMgJ+2IYqES8HBuI0zyNpFLk5vPlZgh7LKmwYBX4HDeNCgEbZSxdeHYm9eV
+
5TVJmgkfW8ZaedU5qNQ4kexQQFissowIOTtXGLV2AKIR6AP0pjTlxX8lubjEQixv
+
2QIDAQAB
+
-----END PUBLIC KEY-----
+
-----BEGIN CERTIFICATE-----
+
MIIDXjCCAkagAwIBAgIETEnNADANBgkqhkiG9w0BAQUFADBxMQswCQYDVQQGEwJV
+
SzEQMA4GA1UECBMHVW5rbm93bjERMA8GA1UEBxMIV2V0aGVyYnkxEDAOBgNVBAoT
+
B1Vua25vd24xEDAOBgNVBAsTB1Vua25vd24xGTAXBgNVBAMTEENpYXJhbiBHdWx0
+
bmlla3MwHhcNMTAwNzIzMTcxMDI0WhcNMzcxMjA4MTcxMDI0WjBxMQswCQYDVQQG
+
EwJVSzEQMA4GA1UECBMHVW5rbm93bjERMA8GA1UEBxMIV2V0aGVyYnkxEDAOBgNV
+
BAoTB1Vua25vd24xEDAOBgNVBAsTB1Vua25vd24xGTAXBgNVBAMTEENpYXJhbiBH
+
dWx0bmlla3MwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCW0HXkfAFO
+
eCLIn9Z/eV0jID4qiEP1O6Tmsb9fL9DiJZOCZ8/K5/v0/lljRq+69AcP25H2b7zf
+
I0ij2SQwUCgk+AUXsVb6sAgJvcjmMb+pr9QtkEWrX9bSjZ4UCvwTAJF7GbfGxN9K
+
SUzx98tKY8gNc0Jl1zWvnk8JRV9CeqZaU1Y/h7M2yiwZ0kT8u6YXugsZ5W7TSv4L
+
JTq5Hi/bEnHxuePDIyAn7YhioRLwcG4jTPI2kUuTm8+VmCHssqbBgFfgcN40KARt
+
lLF14dib15XlNUmaCR9bxlp51Tmo1DiR7FBAWKyyjAg5O1cYtXYAohHoA/SmNOXF
+
fyW5uMRCLG/ZAgMBAAEwDQYJKoZIhvcNAQEFBQADggEBAAjk72memAdnf/VnU9pz
+
77I5DVriwX5NtpHV33p7YPwHGuUJxUFL59XadN8oEeg9NmjEoLGryEufp9lrTN8w
+
u6aFF60qk+IzsEKXKsBVOkgByevge/V+vpo7PW1mOWUmDlDzuPRtsFMXYeYDQKK9
+
3DQmCYOX/aVARKF+UkRUn5hptGDKXm4ha29qLbBYC0gMoq/m7GtG7trPpKpFA4gJ
+
7ODFl4ZT1shfZ45/WiFW0b7dgRd1HmSksNzRQPMECwIYIajZOu2NAbo222yCNyIR
+
/tcU2aMmBwOM39VlvVKf/GNyEqqiwiTvIrYD7M77W/HghcGR1LJP50KxerP1XU5v
+
Be8=
+
-----END CERTIFICATE-----
+
</pre>
+
 
+
== fdroidserver ==
+
 
+
* git repo: https://gitlab.com/fdroid/fdroidserver
+
** git tags signed by "Daniel Martí <mvdan@mvdan.cc>" aka "Daniel Martí <mvdan@fsfe.org>" with fingerprint: <br /><code>A9DA 13CD F7A1 4ACD D3DE  E530 F4CA FFDB 4348 041C</code>
+
** release command: <code>git tag -s</code>
+
 
+
* source package: https://pypi.python.org/pypi/fdroidserver
+
** package tags signed by "Hans-Christoph Steiner <hans@guardianproject.info>" aka "Hans-Christoph Steiner <hans@eds.org>" aka "Hans-Christoph Steiner <hans@at.or.at>" with fingerprint: <br /><code>EE66 20C7 136B 0D2C 456C  0A4D E9E2 8DEA 00AA 5556</code> or previously <br /><code>5E61 C878 0F86 295C E17D  8677 9F0F E587 374B BE81</code>
+
** release command: <code>python setup.py sdist upload --sign</code>
+
 
+
* official Debian package: https://packages.debian.org/fdroidserver
+
** package source: https://alioth.debian.org/anonscm/git/collab-maint/fdroidserver.git
+
** package tags signed by "Hans-Christoph Steiner <hans@guardianproject.info>" aka "Hans-Christoph Steiner <hans@eds.org>" aka "Hans-Christoph Steiner <hans@at.or.at>" with fingerprint: <br /><code>EE66 20C7 136B 0D2C 456C  0A4D E9E2 8DEA 00AA 5556</code> or previously <br /><code>5E61 C878 0F86 295C E17D  8677 9F0F E587 374B BE81</code>
+
** release command: <code>git-buildpackage --git-tag --git-sign-tags</code>
+
 
+
 
+
== Privileged Extension ==
+
 
+
* git repo: https://gitlab.com/fdroid/privileged-extension
+
** git tags signed by "Hans-Christoph Steiner <hans@guardianproject.info>" aka "Hans-Christoph Steiner <hans@eds.org>" aka "Hans-Christoph Steiner <hans@at.or.at>" with fingerprint: <br /><code>EE66 20C7 136B 0D2C 456C  0A4D E9E2 8DEA 00AA 5556</code>
+
** release command: <code>git tag -s</code>
+

Latest revision as of 13:59, 17 October 2017

moved to https://f-droid.org/docs/Release_Channels_and_Signing_Keys