Skip to main content

Re: [VOTE] 4.4.0 RC3

Thanks to David for pointing out this issue. I opened https://issues.apache.org/jira/browse/KAFKA-21208 to improve our release flow. On 2026/10/02 08:56:23 David Jacot wrote: > Hi Omnia, > > Thanks again for running the release. > > While verifying RC3, I found an issue with the signatures of the Maven > artifacts. The source and binary artifacts are fine, as Bill reported, > but most of the Maven artifacts cannot be verified with gpg. Here is how > to reproduce it. > > Setup: > > curl -sO https://downloads.apache.org/kafka/KEYS > gpg --import KEYS > D=https://dist.apache.org/repos/dist/dev/kafka/4.4.0-rc3 > M=https://repository.apache.org/content/groups/staging/org/apache/kafka > > 1) Binary tarball (dist): OK > > curl -sO $D/kafka_2.13-4.4.0.tgz > curl -sO $D/kafka_2.13-4.4.0.tgz.asc > gpg --verify kafka_2.13-4.4.0.tgz.asc kafka_2.13-4.4.0.tgz > > gpg: Signature made Tue Sep 29 14:24:00 2026 CEST > gpg: using RSA key 1817905E3B2708B11A24B88E9AFA6F66CC8C3534 > gpg: Good signature from "Omnia Ibrahim <omnia@apache.org>" [unknown] > gpg: Signature notation: manu=2,2.5+1.12,0,3 > gpg: WARNING: This key is not certified with a trusted signature! > gpg: There is no indication that the signature belongs to the owner. > Primary key fingerprint: 1817 905E 3B27 08B1 1A24 B88E 9AFA 6F66 CC8C 3534 > > 2) streams-quickstart-java (Maven staging): OK > > curl -sO $M/streams-quickstart-java/4.4.0/streams-quickstart-java-4.4.0.jar > curl -sO $M/streams-quickstart-java/4.4.0/streams-quickstart-java-4.4.0.jar.asc > gpg --verify streams-quickstart-java-4.4.0.jar.asc > streams-quickstart-java-4.4.0.jar > > gpg: Signature made Tue Sep 29 16:26:10 2026 CEST > gpg: using RSA key 1817905E3B2708B11A24B88E9AFA6F66CC8C3534 > gpg: Good signature from "Omnia Ibrahim <omnia@apache.org>" [unknown] > gpg: Signature notation: manu=2,2.5+1.12,0,3 > gpg: WARNING: This key is not certified with a trusted signature! > gpg: There is no indication that the signature belongs to the owner. > Primary key fingerprint: 1817 905E 3B27 08B1 1A24 B88E 9AFA 6F66 CC8C 3534 > > 3) kafka-clients (Maven staging): FAILS > > curl -sO $M/kafka-clients/4.4.0/kafka-clients-4.4.0.jar > curl -sO $M/kafka-clients/4.4.0/kafka-clients-4.4.0.jar.asc > gpg --verify kafka-clients-4.4.0.jar.asc kafka-clients-4.4.0.jar > > gpg: Signature made Tue Sep 29 16:20:08 2026 CEST > gpg: using RSA key 24E094AAF3FE292C > gpg: Can't check signature: No public key > > The difference is the key used to sign. Your key in KEYS has two parts: > > pub rsa4096/9AFA6F66CC8C3534 2026-08-21 [SC] [expires: 2028-08-20] > 1817905E3B2708B11A24B88E9AFA6F66CC8C3534 > uid [ unknown] Omnia Ibrahim <omnia@apache.org> > sub rsa4096/24E094AAF3FE292C 2026-08-21 [E] [expires: 2028-08-20] > DDCA6FE8A67A444DD16D35A824E094AAF3FE292C > > The tarball and streams-quickstart-java are signed with the primary key > (9AFA6F66CC8C3534, flagged [SC], so it is allowed to sign). > kafka-clients is signed with the subkey 24E094AAF3FE292C, which is > encryption-only ([E]). gpg only accepts signatures made by keys that are > allowed to sign, hence "No public key" even though the subkey is in > KEYS. > > It looks like the artifacts published by Gradle picked up the wrong key. > I checked 13 of them, including kafka-clients, kafka-streams, > kafka_2.13, kafka-server and connect-runtime, and all are signed with > the subkey. Only streams-quickstart and streams-quickstart-java, which > are published with mvn, are signed with the primary key. For reference, > I verified a few recent releases (4.2.x and 4.3.x) and they all used the > same key to sign the Maven artifacts and the source and binary > artifacts. > > Best, > David >

Comments