Currently we sign this repository using a RSA key in PEM format that just so happens to use the same set of random bytes as our 2021 Release Signing Key, which is an rsa4096 PGP key.
We're rotating our PGP signing key (https://securedrop.org/news/new-release-signing-key/), so we should move away from the current RSA key. We've also separately generated a standalone ed25519 key that we could end up using for this signing process.
We need to figure out the exact signing story, but once we're ready we should sign the current ruleset in parallel and work upstream with Tor Browser to get the configuration updated.
Possibly linked to #269.
Currently we sign this repository using a RSA key in PEM format that just so happens to use the same set of random bytes as our 2021 Release Signing Key, which is an rsa4096 PGP key.
We're rotating our PGP signing key (https://securedrop.org/news/new-release-signing-key/), so we should move away from the current RSA key. We've also separately generated a standalone ed25519 key that we could end up using for this signing process.
We need to figure out the exact signing story, but once we're ready we should sign the current ruleset in parallel and work upstream with Tor Browser to get the configuration updated.
Possibly linked to #269.