Hi Omnia, Thanks again for running the release. While verifying RC3, I found an issue with the signatures of the Maven artifacts. The source and binary artifacts are fine, as Bill reported, but most of the Maven artifacts cannot be verified with gpg. Here is how to reproduce it. Setup: curl -sO https://downloads.apache.org/kafka/KEYS gpg --import KEYS D=https://dist.apache.org/repos/dist/dev/kafka/4.4.0-rc3 M=https://repository.apache.org/content/groups/staging/org/apache/kafka 1) Binary tarball (dist): OK curl -sO $D/kafka_2.13-4.4.0.tgz curl -sO $D/kafka_2.13-4.4.0.tgz.asc gpg --verify kafka_2.13-4.4.0.tgz.asc kafka_2.13-4.4.0.tgz gpg: Signature made Tue Sep 29 14:24:00 2026 CEST gpg: using RSA key 1817905E3B2708B11A24B88E9AFA6F66CC8C3534 gpg: Good signature from "Omnia Ibrahim <omnia@apache.org>" [unknown] gpg: Signature notation: manu=2,2.5+1.12,0,3 gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Primary key fingerprint: 1817 905E 3B27 08B1 1A24 B88E 9AFA 6F66 CC8C 3534 2) streams-quickstart-java (Maven staging): OK curl -sO $M/streams-quickstart-java/4.4.0/streams-quickstart-java-4.4.0.jar curl -sO $M/streams-quickstart-java/4.4.0/streams-quickstart-java-4.4.0.jar.asc gpg --verify streams-quickstart-java-4.4.0.jar.asc streams-quickstart-java-4.4.0.jar gpg: Signature made Tue Sep 29 16:26:10 2026 CEST gpg: using RSA key 1817905E3B2708B11A24B88E9AFA6F66CC8C3534 gpg: Good signature from "Omnia Ibrahim <omnia@apache.org>" [unknown] gpg: Signature notation: manu=2,2.5+1.12,0,3 gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Primary key fingerprint: 1817 905E 3B27 08B1 1A24 B88E 9AFA 6F66 CC8C 3534 3) kafka-clients (Maven staging): FAILS curl -sO $M/kafka-clients/4.4.0/kafka-clients-4.4.0.jar curl -sO $M/kafka-clients/4.4.0/kafka-clients-4.4.0.jar.asc gpg --verify kafka-clients-4.4.0.jar.asc kafka-clients-4.4.0.jar gpg: Signature made Tue Sep 29 16:20:08 2026 CEST gpg: using RSA key 24E094AAF3FE292C gpg: Can't check signature: No public key The difference is the key used to sign. Your key in KEYS has two parts: pub rsa4096/9AFA6F66CC8C3534 2026-08-21 [SC] [expires: 2028-08-20] 1817905E3B2708B11A24B88E9AFA6F66CC8C3534 uid [ unknown] Omnia Ibrahim <omnia@apache.org> sub rsa4096/24E094AAF3FE292C 2026-08-21 [E] [expires: 2028-08-20] DDCA6FE8A67A444DD16D35A824E094AAF3FE292C The tarball and streams-quickstart-java are signed with the primary key (9AFA6F66CC8C3534, flagged [SC], so it is allowed to sign). kafka-clients is signed with the subkey 24E094AAF3FE292C, which is encryption-only ([E]). gpg only accepts signatures made by keys that are allowed to sign, hence "No public key" even though the subkey is in KEYS. It looks like the artifacts published by Gradle picked up the wrong key. I checked 13 of them, including kafka-clients, kafka-streams, kafka_2.13, kafka-server and connect-runtime, and all are signed with the subkey. Only streams-quickstart and streams-quickstart-java, which are published with mvn, are signed with the primary key. For reference, I verified a few recent releases (4.2.x and 4.3.x) and they all used the same key to sign the Maven artifacts and the source and binary artifacts. Best, David
Comments
Post a Comment