This APT repository is signed with the following GPG key:
- Fingerprint:
D6F4 7642 A542 4C78 332C CD8E EAD2 766F 4E85 7693 - UID: Dovecot XAPS APT Repo Signing dovecot-xaps-apt@users.noreply.github.com
- Public Key:
public-key.asc
When rotating the signing key:
-
Generate a new 4096-bit RSA key pair locally:
gpg --full-generate-key # RSA 4096, no expiration, no passphrase -
Update
conf/distributionswith the new fingerprint:SignWith: <NEW_FINGERPRINT>
-
Export and commit the new public key:
gpg --export --armor <NEW_KEY_ID> > public-key.asc
-
Re-sign all existing repository metadata:
reprepro --basedir . cleartrust reprepro --basedir . maintainreleases
-
Add the new private key as GitHub Actions secret
APT_SIGNING_PRIVATE_KEY. -
Remove the old private key from GitHub Actions secrets.
-
Update the fingerprint in this file and in
README.md.
If a signing key is compromised:
-
Revoke the compromised key immediately:
gpg --gen-revoke <KEY_ID> > revoke.asc gpg --import revoke.asc
-
Upload the revocation to a keyserver:
gpg --keyserver hkps://keys.openpgp.org --send-keys <KEY_ID>
-
Follow the Key Rotation Procedure above to generate and deploy a new key.
-
Remove the compromised private key from GitHub Actions secrets.
For security issues, please open a private issue or contact the repository maintainer directly.