[ https://issues.apache.org/jira/browse/MNGSITE-485?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17550661#comment-17550661 ]
Michael Osipov commented on MNGSITE-485: ---------------------------------------- Please try again. > Expired signature in provided KEYS file on the download page > ------------------------------------------------------------ > > Key: MNGSITE-485 > URL: https://issues.apache.org/jira/browse/MNGSITE-485 > Project: Maven Project Web Site > Issue Type: Bug > Reporter: Baiyang Li > Assignee: Michael Osipov > Priority: Major > > Hey, > I met the same expired signature issue described in this close > [issue|https://issues.apache.org/jira/browse/MNGSITE-458?page=com.atlassian.jira.plugin.system.issuetabpanels%3Acomment-tabpanel&focusedCommentId=17410236#comment-17410236]. > When i follow the procedure to verify the signature using the KEYS file, both > provided on the maven's download page:: > * KEYS file import: gpg --import KEYS > * signature verification; gpg --verify .\apache-maven-3.8.2-bin.tar.gz.asc > .\apache-maven-3.8.2-bin.tar.gz > I've got the following message at the second step: > gpg: Good signature from "Michael Osipov (Java developer) > <1983-01...@gmx.net>" [expired] > gpg: aka "Michael Osipov <micha...@apache.org>" [expired] > gpg: Note: This key has expired! > According to the same procedure: "A signature is valid, if gpg verifies the > .asc as a good signature, and doesn't complain about expired or revoked > keys", so, technically, the signature is not valid. -- This message was sent by Atlassian Jira (v8.20.7#820007)