Files
acme.sh/allowed_signers
T
neil aafc4efe1f allowed_signers: point the examples at 3.1.6
The comment block told the reader to run "git verify-tag 3.1.5", which is
exactly the tag that fails: 3.1.5 was tagged by the GitHub release form as
a lightweight ref and carries no signature. Use 3.1.6 in the examples and
state the baseline, so the file that teaches verification does not hand out
a command that cannot work.

https://github.com/acmesh-official/acme.sh/issues/7273
2026-09-20 13:13:20 +02:00

23 lines
927 B
Plaintext

# acme.sh release signing key.
#
# Release tags are signed with this key. Its private half is held by the
# maintainer and is never available to CI, so a compromise of the build
# pipeline cannot produce a tag that verifies against this file.
#
# Signing starts at 3.1.6; tags up to 3.1.5 are unsigned.
#
# Fingerprint: SHA256:M60qVafm/NUywQHXAkoQcj2v6KgkfrdSXv6mPejUUeE
#
# To verify a release tag, from a clone of this repository:
#
# git config gpg.ssh.allowedSignersFile allowed_signers
# git verify-tag 3.1.6
#
# A good signature covers the tag object, which pins the commit, which pins
# the whole tree -- so verifying the tag verifies every file at that
# release. Build a tarball from the verified tag with:
#
# git archive --format=tar.gz --prefix=acme.sh-3.1.6/ 3.1.6 > acme.sh-3.1.6.tar.gz
#
github@neilpang.com namespaces="git" ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBTjI0HBJn3uhfT2DsNcFybfAZi3ADbIacMpz1BItKdB