Hey guys,

I was not aware of the possibility to create your own key for subprojects.
I thought it is always inherited from the parent project.

Finally, after creating it’s own gpg key for science:gr-framework this is sorted out.


On 18. Oct 2021, at 09:22, Felder, Christian <c.felder@fz-juelich.de> wrote:

Am 18.10.2021 um 08:38 schrieb Adrian Schröter <adrian@suse.de>:

On Montag, 18. Oktober 2021, 08:34:17 CEST Adrian Schröter wrote:
On Sonntag, 17. Oktober 2021, 21:04:18 CEST Felder, Christian wrote:
Hi all,

I am sorry for reviving this old thread, but unfortunately this is still a thing.

The science gpg key is still using dsa1024 which is considered too weak especially by Ubuntu systems.

As the key will expire soon (2021-11-11), is there any chance to upgrade to another signature algorithm?

pub   dsa1024 2008-01-22 [SC] [expires: 2021-11-11]
uid           science OBS Project <science@build.opensuse.org <mailto:science@build.opensuse.org>>

any maintainer could call

osc signkey --create science

to create a new key. But there is no way to migrate a key from dsa to rsa.

just to be explicit here: A new key will of course mean that every repository user
of the repository will be prompted about the change.

So any kind of announcement might be necessary ....

The key will be due soon (2021-11-11). I don‘t ask to renew before that, but it would be nice to renew with rsa this time.


Adrian Schroeter <adrian@suse.de>
Build Infrastructure Project Manager

SUSE Software Solutions Germany GmbH,  Maxfeldstr. 5, 90409 Nuernberg, Germany
(HRB 247165, AG München), Geschäftsführer: Felix Imendörffer

Forschungszentrum Juelich GmbH
52425 Juelich
Sitz der Gesellschaft: Juelich
Eingetragen im Handelsregister des Amtsgerichts Dueren Nr. HR B 3498
Vorsitzender des Aufsichtsrats: MinDir Volker Rieke
Geschaeftsfuehrung: Prof. Dr.-Ing. Wolfgang Marquardt (Vorsitzender),
Karsten Beneke (stellv. Vorsitzender), Dr. Astrid Lambrecht,
Prof. Dr. Frauke Melchior