Flink 1.6.4 signing key file in docker-flink repo?

classic Classic list List threaded Threaded
2 messages Options
Reply | Threaded
Open this post in threaded view
|

Flink 1.6.4 signing key file in docker-flink repo?

William Saar-2
Trying to build a new Docker image by replacing 1.6.3 with 1.6.4 in the Dockerfile found here ( https://github.com/docker-flink/docker-flink ), but seems to require a new signing key, Is it available somewhere?

Getting
+ wget -nv -O flink.tgz.asc https://www.apache.org/dist/flink/flink-1.6.4/flink-1.6.4-bin-scala_2.11.tgz.asc
2019-02-25 15:58:20 URL:https://www.apache.org/dist/flink/flink-1.6.4/flink-1.6.4-bin-scala_2.11.tgz.asc [833/833] -> "flink.tgz.asc" [1]
+ mktemp -d
+ export GNUPGHOME=/tmp/tmp.fuHAgJfHYL
+ gpg --batch --import /KEYS
gpg: keybox '/tmp/tmp.fuHAgJfHYL/pubring.kbx' created
key 88BD3F5704D9B832:
1 signature not checked due to a missing key
gpg: /tmp/tmp.fuHAgJfHYL/trustdb.gpg: trustdb created
gpg: key 88BD3F5704D9B832: public key "Alan Gates (No comment) <[hidden email]>" imported
gpg: key D5E0A69C0CBAAE9F: public key "Sean Owen (CODE SIGNING KEY) <[hidden email]>" imported
key D056856A0410DA0C:
1 signature not checked due to a missing key
gpg: key D056856A0410DA0C: public key "Ted Dunning (for signing Apache releases) <[hidden email]>" imported
gpg: key EDF4C9583592721E: public key "Henry Saputra (CODE SIGNING KEY) <[hidden email]>" imported
uid  Owen O'Malley <[hidden email]>
sig!3        1209E7F13D0C92B9 2010-09-17  [self-signature]
uid  Owen O'Malley (Code signing) <[hidden email]>
sig!3        1209E7F13D0C92B9 2010-09-17  [self-signature]
sig!3        1209E7F13D0C92B9 2010-02-23  [self-signature]
sub  73F426934D654583
sig!         1209E7F13D0C92B9 2010-02-23  [self-signature]
key 1209E7F13D0C92B9:
8 duplicate signatures removed
47 signatures not checked due to missing keys
gpg: key 1209E7F13D0C92B9: public key "Owen O'Malley (Code signing) <[hidden email]>" imported
gpg: key 183F6944D9839159: public key "Robert Metzger (CODE SIGNING KEY) <[hidden email]>" imported
gpg: key DE3E0F4C9D403309: public key "Ufuk Celebi (CODE SIGNING KEY) <[hidden email]>" imported
gpg: key 2C70877AD675A2E9: public key "Márton Balassi (CODE SIGNING KEY) <[hidden email]>" imported
gpg: key DE976D18C2909CBF: public key "Maximilian Michels <[hidden email]>" imported
gpg: key 600AD0D034911D5A: public key "Fabian Hueske (CODE SIGNING KEY) <[hidden email]>" imported
gpg: key 6D072D73B065B356: public key "Tzu-Li Tai (CODE SIGNING KEY) <[hidden email]>" imported
gpg: key A8F4FD97121D7293: public key "Aljoscha Krettek (CODE SIGNING KEY) <[hidden email]>" imported
gpg: key C2EED7B111D464BA: public key "Chesnay Schepler (CODE SIGNING KEY) <[hidden email]>" imported
gpg: key F320986D35C33D6A: public key "Tzu-Li Tai (CODE SIGNING KEY) <[hidden email]>" imported
gpg: key 1F302569A96CFFD5: public key "Till Rohrmann (stsffap) <[hidden email]>" imported
gpg: key 12DEE3E4D920A98C: public key "Thomas Weise <[hidden email]>" imported
gpg: Total number processed: 16
gpg:               imported: 16
gpg: no ultimately trusted keys found
+ gpg --batch --verify flink.tgz.asc flink.tgz
gpg: Signature made Fri Feb 15 13:13:29 2019 UTC
gpg:                using RSA key 8FEA1EE9D0048C0CCC70B7573211B0703B79EA0E
gpg: Can't check signature: No public key

Thanks,
William
Reply | Threaded
Open this post in threaded view
|

Re: Flink 1.6.4 signing key file in docker-flink repo?

Till Rohrmann
Hi William,

where do you get the /KEYS file from? Have you imported the latest KEYS from here [1]?


Cheers,
Till

On Mon, Feb 25, 2019 at 5:16 PM William Saar <[hidden email]> wrote:
Trying to build a new Docker image by replacing 1.6.3 with 1.6.4 in the Dockerfile found here ( https://github.com/docker-flink/docker-flink ), but seems to require a new signing key, Is it available somewhere?

Getting
+ wget -nv -O flink.tgz.asc https://www.apache.org/dist/flink/flink-1.6.4/flink-1.6.4-bin-scala_2.11.tgz.asc
2019-02-25 15:58:20 URL:https://www.apache.org/dist/flink/flink-1.6.4/flink-1.6.4-bin-scala_2.11.tgz.asc [833/833] -> "flink.tgz.asc" [1]
+ mktemp -d
+ export GNUPGHOME=/tmp/tmp.fuHAgJfHYL
+ gpg --batch --import /KEYS
gpg: keybox '/tmp/tmp.fuHAgJfHYL/pubring.kbx' created
key 88BD3F5704D9B832:
1 signature not checked due to a missing key
gpg: /tmp/tmp.fuHAgJfHYL/trustdb.gpg: trustdb created
gpg: key 88BD3F5704D9B832: public key "Alan Gates (No comment) <[hidden email]>" imported
gpg: key D5E0A69C0CBAAE9F: public key "Sean Owen (CODE SIGNING KEY) <[hidden email]>" imported
key D056856A0410DA0C:
1 signature not checked due to a missing key
gpg: key D056856A0410DA0C: public key "Ted Dunning (for signing Apache releases) <[hidden email]>" imported
gpg: key EDF4C9583592721E: public key "Henry Saputra (CODE SIGNING KEY) <[hidden email]>" imported
uid  Owen O'Malley <[hidden email]>
sig!3        1209E7F13D0C92B9 2010-09-17  [self-signature]
uid  Owen O'Malley (Code signing) <[hidden email]>
sig!3        1209E7F13D0C92B9 2010-09-17  [self-signature]
sig!3        1209E7F13D0C92B9 2010-02-23  [self-signature]
sub  73F426934D654583
sig!         1209E7F13D0C92B9 2010-02-23  [self-signature]
key 1209E7F13D0C92B9:
8 duplicate signatures removed
47 signatures not checked due to missing keys
gpg: key 1209E7F13D0C92B9: public key "Owen O'Malley (Code signing) <[hidden email]>" imported
gpg: key 183F6944D9839159: public key "Robert Metzger (CODE SIGNING KEY) <[hidden email]>" imported
gpg: key DE3E0F4C9D403309: public key "Ufuk Celebi (CODE SIGNING KEY) <[hidden email]>" imported
gpg: key 2C70877AD675A2E9: public key "Márton Balassi (CODE SIGNING KEY) <[hidden email]>" imported
gpg: key DE976D18C2909CBF: public key "Maximilian Michels <[hidden email]>" imported
gpg: key 600AD0D034911D5A: public key "Fabian Hueske (CODE SIGNING KEY) <[hidden email]>" imported
gpg: key 6D072D73B065B356: public key "Tzu-Li Tai (CODE SIGNING KEY) <[hidden email]>" imported
gpg: key A8F4FD97121D7293: public key "Aljoscha Krettek (CODE SIGNING KEY) <[hidden email]>" imported
gpg: key C2EED7B111D464BA: public key "Chesnay Schepler (CODE SIGNING KEY) <[hidden email]>" imported
gpg: key F320986D35C33D6A: public key "Tzu-Li Tai (CODE SIGNING KEY) <[hidden email]>" imported
gpg: key 1F302569A96CFFD5: public key "Till Rohrmann (stsffap) <[hidden email]>" imported
gpg: key 12DEE3E4D920A98C: public key "Thomas Weise <[hidden email]>" imported
gpg: Total number processed: 16
gpg:               imported: 16
gpg: no ultimately trusted keys found
+ gpg --batch --verify flink.tgz.asc flink.tgz
gpg: Signature made Fri Feb 15 13:13:29 2019 UTC
gpg:                using RSA key 8FEA1EE9D0048C0CCC70B7573211B0703B79EA0E
gpg: Can't check signature: No public key

Thanks,
William