)]}'
{"/PATCHSET_LEVEL":[{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"974106318de81e80ff018873462dd72aec9b4f47","unresolved":false,"context_lines":[],"source_content_type":"","patch_set":1,"id":"a562d6cf_b34c93f2","updated":"2021-10-27 08:41:33.000000000","message":"lgtm initially, will update the attestation section as the discussion proceeds","commit_id":"738f42760aded75fe0963ff25d589f908f9b5fd4"}],"doc/source/signing.rst":[{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"593f8031bd419dc404efb050bc4e47095fe26a89","unresolved":false,"context_lines":[{"line_number":481,"context_line":"individual key signatures we can\u0027t easily distribute to users. For"},{"line_number":482,"context_line":"now, we simply make sure the signature made by the previous key is"},{"line_number":483,"context_line":"included in the export we publish from our own sites so that users"},{"line_number":484,"context_line":"can have some path to confirm new keys."},{"line_number":485,"context_line":""},{"line_number":486,"context_line":"Still, please retrieve a copy of the"},{"line_number":487,"context_line":"``/root/signing.gnupg/some.revoke.asc`` fallback revocation"}],"source_content_type":"text/x-rst","patch_set":1,"id":"30f7c05f_e6ca560d","line":484,"updated":"2021-10-27 11:26:17.000000000","message":"In fact, thinking about it a bit more, that validation could be automated in Zuul too.","commit_id":"738f42760aded75fe0963ff25d589f908f9b5fd4"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"723ef02c3f4bc7c7f270ecb9fe47b23a61eee998","unresolved":true,"context_lines":[{"line_number":481,"context_line":"individual key signatures we can\u0027t easily distribute to users. For"},{"line_number":482,"context_line":"now, we simply make sure the signature made by the previous key is"},{"line_number":483,"context_line":"included in the export we publish from our own sites so that users"},{"line_number":484,"context_line":"can have some path to confirm new keys."},{"line_number":485,"context_line":""},{"line_number":486,"context_line":"Still, please retrieve a copy of the"},{"line_number":487,"context_line":"``/root/signing.gnupg/some.revoke.asc`` fallback revocation"}],"source_content_type":"text/x-rst","patch_set":1,"id":"5ba1a02e_ee16267d","line":484,"updated":"2021-10-27 07:37:48.000000000","message":"Where does https://releases.openstack.org/#cryptographic-signatures come from? (n.b. we should drop the now non-functional links to sks there)\n\nI also think that there would be value in adding our signatures to the keys that get published there, likely we could collect the signatures in a local copy on bridge pretty easily.","commit_id":"738f42760aded75fe0963ff25d589f908f9b5fd4"},{"author":{"_account_id":5263,"name":"Jeremy Stanley","display_name":"fungi","email":"fungi@yuggoth.org","username":"fungi","status":"missing, presumed fed"},"change_message_id":"6dbe923aeafbd1e071c72b28a3376473ce916cb0","unresolved":false,"context_lines":[{"line_number":481,"context_line":"individual key signatures we can\u0027t easily distribute to users. For"},{"line_number":482,"context_line":"now, we simply make sure the signature made by the previous key is"},{"line_number":483,"context_line":"included in the export we publish from our own sites so that users"},{"line_number":484,"context_line":"can have some path to confirm new keys."},{"line_number":485,"context_line":""},{"line_number":486,"context_line":"Still, please retrieve a copy of the"},{"line_number":487,"context_line":"``/root/signing.gnupg/some.revoke.asc`` fallback revocation"}],"source_content_type":"text/x-rst","patch_set":1,"id":"36fdbade_58c674e0","line":484,"updated":"2021-10-27 11:24:59.000000000","message":"Yes, in both senses I think a followup would be fine (a followup to this process change in order to restore some of the attestation steps, but also the additions of keysigs can happen in follow-ups to the releases repo change as well). The main problem with the latter is that it\u0027s not trivial to review updates to the exported key, though I suppose we can write instructions for that as well (make sure you have the public keys from keysigs listed in the comment block, then import the key blob from the checked out change and view the keysigs on it locally).","commit_id":"738f42760aded75fe0963ff25d589f908f9b5fd4"},{"author":{"_account_id":13252,"name":"Dr. Jens Harbott","display_name":"Jens Harbott (frickler)","email":"frickler@offenerstapel.de","username":"jrosenboom"},"change_message_id":"974106318de81e80ff018873462dd72aec9b4f47","unresolved":true,"context_lines":[{"line_number":481,"context_line":"individual key signatures we can\u0027t easily distribute to users. For"},{"line_number":482,"context_line":"now, we simply make sure the signature made by the previous key is"},{"line_number":483,"context_line":"included in the export we publish from our own sites so that users"},{"line_number":484,"context_line":"can have some path to confirm new keys."},{"line_number":485,"context_line":""},{"line_number":486,"context_line":"Still, please retrieve a copy of the"},{"line_number":487,"context_line":"``/root/signing.gnupg/some.revoke.asc`` fallback revocation"}],"source_content_type":"text/x-rst","patch_set":1,"id":"0ed9b567_7e1de64b","line":484,"in_reply_to":"5ba1a02e_ee16267d","updated":"2021-10-27 08:41:33.000000000","message":"Oh, I found https://review.opendev.org/c/openstack/releases/+/815550. Maybe signers could simply update that review with keys that have their sigs added? Or add as followups? I\u0027m going to go for the latter which will be easier to abandon in case people disagree.","commit_id":"738f42760aded75fe0963ff25d589f908f9b5fd4"}]}
