Skip to content
MostlyDoneMostlyDone

Security

Custodian release signing key

Every custodian release ships a checksums.txt signed with the key below. Check this fingerprint against the copy in the release you downloaded, then verify the checksum file's signature — that is how you know the artefacts are ours.

Published keys

This is one of three places the signing key is published — the others are thesigning/ directory of the source repository and the notes of every release. A substitution has to succeed in more than one of them to go unnoticed, so a reviewer who finds them disagreeing has learned something. Keys are never removed: a retired key stays listed so an older release can still be verified.

  • custodian-release-signing-key (2026)

    Current
    SHA-256 fingerprint
    sha256:b477412e8852c1f35f0f1094cdf66527272ecc95b8faccebfc6e0a2070b67fba
    Algorithm
    ECDSA P-256 (secp256r1), SHA-256
    Published
    Signing from
    Signing until
    Still current

    Public key (PEM)

    -----BEGIN PUBLIC KEY-----
    MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE/h28LLwbOyCexqaBLZRceOq2SeBH
    Br8V4encwNTCoNEh8447DucGXR+zwr5g9tPGDInJ8HCzQw04VN8oktGxEQ==
    -----END PUBLIC KEY-----

What this key signs

Each custodian release publishes two checksum files, and the current key signs the first of them intochecksums.txt.sig:

  • checksums.txt — SHA-256 of every published release artefact.
  • checksums-unsigned.txt — SHA-256 of the same artefacts as a rebuild from source reproduces them, so a reproducible build can be compared against what was released.

Verify a release

With openssl and sha256sum alone. First save the key above to custodian-release-signing-key.pub.pem, then:

# 1. the checksum file's signature is ours
openssl dgst -sha256 \
  -verify custodian-release-signing-key.pub.pem \
  -signature checksums.txt.sig \
  checksums.txt

# 2. the downloaded artefact matches the (signed) checksum file
sha256sum -c --ignore-missing checksums.txt

You can recompute the fingerprint above from the key file to confirm it is the one you saved:

openssl pkey -pubin -in custodian-release-signing-key.pub.pem -outform DER \
  | sha256sum

The full step-by-step verification procedure — including rebuilding from the published source archive and comparing against checksums-unsigned.txt — is published withevery custodian release.