Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Validating Authenticity of a key

You may download public keys for the Apache Fineract release managers from our website or retrieve them off the public PGP key servers (see above). However, importing these keys is not enough to verify the integrity of the signatures. If a release verifies as good, you need to validate that the key was created by an official representative of the Apache Fineract Project.

The crucial step to validation is to confirm the key fingerprint of the public key.

 

Code Block
languagebash
% gpg --fingerprint 0BB29444

pub   4096R/0BB29444 2016-06-29
      Key fingerprint = AF4F D65D E78C A5B1 BF30  939F 80C4 D889 0BB2 9444
uid       [ unknown] Shaik Nazeer Hussain (CODE SIGNING KEY) <nazeer1100126@apache.org>
sub   4096R/F11A0D70 2016-06-29