Skip Menu |

This queue is for tickets about the Search-GIN CPAN distribution.

Report information
The Basics
Id: 56478
Status: resolved
Priority: 0/
Queue: Search-GIN

People
Owner: Nobody in particular
Requestors: daxim [...] cpan.org
Cc:
AdminCc:

Bug Information
Severity: (no value)
Broken in: 0.04
Fixed in: (no value)



Subject: signature_verify NO: key 7A90BC7B6252F1E7 not found on keyserver
~/.cpan/build/Search-GIN-0.04> cpansign -v Executing gpg --verify --batch --no-tty --keyserver=hkp://pool.sks-keyservers.net:11371 --keyserver-options=auto-key-retrieve SIGNATURE gpg: Signature made Thu Mar 4 13:14:31 2010 CET using DSA key ID 6252F1E7 gpg: requesting key 6252F1E7 from hkp server pool.sks-keyservers.net gpgkeys: key 7A90BC7B6252F1E7 not found on keyserver gpg: no valid OpenPGP data found. gpg: Total number processed: 0 gpg: Can't check signature: No public key ==> BAD/TAMPERED signature detected! <==
Since previous versions were released with SIGNATURE, I released 0.04 with one as well. However, as it seems, I forgot to transfer the key to a keyserver so it wasn't just pointless but actually created a sense of "insecurity" for the release. That's bad! :) I just released 0.05 with a correct signature that is on a public keyserver and I've verified it myself. Thank you for the report and apologies for the error. S.