@@ -21,11 +21,9 @@ downloaded over HTTPS. Checksum of the tarball is not checked after downloading.
2121 download a release, Chisel reads the Etag from cache and checks whether the
2222 cache is still valid. If it is valid, the cached release YAMLs are used.
2323
24- 1 . Chisel downloads a few * InRelease* files from the [ Ubuntu Archive
25- but] ( http://archive.ubuntu.com ) these files are never cached. The InRelease
26- files are signed by GPG, and Chisel verifies[ ^ 3 ] the integrity using the [ Ubuntu
27- Archive Automatic Signing
28- Key] ( https://keyserver.ubuntu.com/pks/lookup?search=f6ecb3762474eda9d21b7022871920d1991bc93c&fingerprint=on&op=index ) .[ ^ 4 ]
24+ 1 . Chisel downloads a few * InRelease* files from the [ Ubuntu Archive] ( http://archive.ubuntu.com ) but these files are never cached. The InRelease
25+ files are signed by GPG, and Chisel verifies[ ^ 3 ] the integrity using the <a href="https://keyserver.ubuntu.com/pks/lookup?search=f6ecb3762474eda9
26+ d21b7022871920d1991bc93c&fingerprint=on&op=index">Ubuntu Archive Automatic Signing Key</a >[ ^ 4 ] .
2927The key is specified in the [ chisel.yaml in
3028chisel-releases] ( https://github.com/canonical/chisel-releases/blob/a442b2e7208128df6366f859b7a858c0d3fce925/chisel.yaml#L47 ) .
3129The Go package [ golang.org/x/crypto/openpgp] ( http://golang.org/x/crypto/openpgp )
@@ -61,9 +59,8 @@ to verify the signed InRelease files it downloads from the Ubuntu Archive. This
6159file (chisel.yaml) is exposed to the user and Users can very much specify a
6260different key on their forks.
6361
64- The default public key in the official repository is the RSA/4096-bit [ Ubuntu
65- Archive Automatic Signing Key
66- (2018)] ( https://keyserver.ubuntu.com/pks/lookup?search=f6ecb3762474eda9d21b7022871920d1991bc93c&fingerprint=on&op=index )
62+ The default public key in the official repository is the RSA/4096-bit <a href="https://keyserver.ubuntu.com/pks/lookup?search=f6ecb37624
63+ 74eda9d21b7022871920d1991bc93c&fingerprint=on&op=index">Ubuntu Archive Automatic Signing Key (2018)</a >
6764with ID 871920D1991BC93C.
6865
6966```
0 commit comments