You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commons-dev@ws.apache.org by Dan Diephouse <da...@envoisolutions.com> on 2006/02/25 18:19:47 UTC

Signing Releases Re: Vote Passed [was Re: [Vote] Release XmlSchema 1.0]

Sorry for all the email while I try to figure out how to do releases, 
but I'm down to one last question. Do I need to be initiated into the 
web of trust to make releases? I created my own GPG key, signed the 
files, then uploaded the signatures:

http://www.apache.org/dist/maven-repository/org/apache/ws/commons/XmlSchema/1.0/

I just can't figure out what the web of trust has to do with it...

http://www.apache.org/dev/release-signing.html

- Dan

Dan Diephouse wrote:
> No worries. I wasn't in a particular hurry, was just hoping to get it 
> done sometime this weekend while I had some time. The new site is up 
> and the release is pushed. Only thing left to do now is figure out PGP 
> key signing. Will conquer that in a few hours then send out a release 
> announcement!
>
> - Dan
>
> Sanjiva Weerawarana wrote:
>> Ummmmm. ARGH.
>>
>> Sorry Dan, scratch the mail below please. I'm on drugs. My apologies; I
>> see that I myself voted for it more than 72 hours ago ;-).
>>
>> Sanjiva.
>>
>> On Sat, 2006-02-25 at 06:02 +0600, Sanjiva Weerawarana wrote:
>>  
>>> On Fri, 2006-02-24 at 11:36 -0500, Dan Diephouse wrote:
>>>    
>>>> Did I forget to add my +1? :-) Adding it in, we have 5 +1s and no 
>>>> -1s. I'll be doing the release this afternoon (EST) and getting the 
>>>> website updated as well.
>>>>       
>>> Um for some reason I didn't see this vote coming thru. Was it on
>>> commons-dev?? Hmm my filters must be screwed up.
>>>
>>> When was it called? Has it been 72 hrs since the vote? If not the vote
>>> is not closed and you cannot release. I know you're in a hurry but 
>>> let's
>>> slow down just a little bit please :).
>>>
>>> Sanjiva.
>>>     
>>
>>   
>
>


-- 
Dan Diephouse
Envoi Solutions LLC
http://envoisolutions.com
http://netzooid.com/blog


Re: Signing Releases Re: Vote Passed [was Re: [Vote] Release XmlSchema 1.0]

Posted by Dan Diephouse <da...@envoisolutions.com>.
Eran Chinthaka wrote:
> Hi Dan,
>
> Dan Diephouse wrote:
>
>   
>> Just an update: I can't create a KEYS file for XmlSchema because I
>> don't have write permissions to /www/www.apache.org/dist/ws.
>>     
>
> You must create the KEYS file in /www/www.apache.org/dist/ws/commons,
> not in /www/www.apache.org/dist/ws. I made the commons folder and gave
> group rights for that.
>
>   
The point here is that I'm not in the "ws" group so I can't create 
folders or write to the folder that you just created :-). I think I need 
to wait for dims to reappear for me to be able to do that.

>> I noticed that lots of apache releases aren't signed? Is it a
>> requirement that people sign them? Does anyone actually use these
>> signatures???
>>     
>
> I don't think lot of releases are still not signed. I could remember
> this question was raised during ApacheCon Europe last year and infra
> people didn't wanna happen that.
> Anyway, I prefer if we sign all the releases,  we make sure the users
> will get proper releases all the time.
>
> Henk Penning will tell you know more abt this, I think.
>
> -- Chinthaka
>
>   
OK, thanks.

- Dan

-- 
Dan Diephouse
Envoi Solutions LLC
http://envoisolutions.com
http://netzooid.com/blog


Re: Signing Releases Re: Vote Passed [was Re: [Vote] Release XmlSchema 1.0]

Posted by Eran Chinthaka <ch...@opensource.lk>.
Hi Dan,

Dan Diephouse wrote:

> Just an update: I can't create a KEYS file for XmlSchema because I
> don't have write permissions to /www/www.apache.org/dist/ws.

You must create the KEYS file in /www/www.apache.org/dist/ws/commons,
not in /www/www.apache.org/dist/ws. I made the commons folder and gave
group rights for that.

>
> I noticed that lots of apache releases aren't signed? Is it a
> requirement that people sign them? Does anyone actually use these
> signatures???

I don't think lot of releases are still not signed. I could remember
this question was raised during ApacheCon Europe last year and infra
people didn't wanna happen that.
Anyway, I prefer if we sign all the releases,  we make sure the users
will get proper releases all the time.

Henk Penning will tell you know more abt this, I think.

-- Chinthaka


Re: Signing Releases Re: Vote Passed [was Re: [Vote] Release XmlSchema 1.0]

Posted by Srinath Perera <he...@gmail.com>.
Hi Dan;

Oops you are having a real hard time on it.

1) AFAIK web of trust is highly encouraged, nut unless somebody else
say otherwise go ahead and do the relase with the signature you create
for files.

2) Sent me the KEYS file, I will upload it.

3) Send a mail to general@ws.apache.org asking for the adding you to
ws group, or your nightmare will continue. I think Dims is the guy to
catch

Thanks
Srinath





On 2/27/06, Dan Diephouse <da...@envoisolutions.com> wrote:
> Just an update: I can't create a KEYS file for XmlSchema because I don't
> have write permissions to /www/www.apache.org/dist/ws.
>
> I noticed that lots of apache releases aren't signed? Is it a
> requirement that people sign them? Does anyone actually use these
> signatures???
>
> - Dan
>
> Dan Diephouse wrote:
> > Sorry for all the email while I try to figure out how to do releases,
> > but I'm down to one last question. Do I need to be initiated into the
> > web of trust to make releases? I created my own GPG key, signed the
> > files, then uploaded the signatures:
> >
> > http://www.apache.org/dist/maven-repository/org/apache/ws/commons/XmlSchema/1.0/
> >
> >
> > I just can't figure out what the web of trust has to do with it...
> >
> > http://www.apache.org/dev/release-signing.html
> >
> > - Dan
> >
> > Dan Diephouse wrote:
> >> No worries. I wasn't in a particular hurry, was just hoping to get it
> >> done sometime this weekend while I had some time. The new site is up
> >> and the release is pushed. Only thing left to do now is figure out
> >> PGP key signing. Will conquer that in a few hours then send out a
> >> release announcement!
> >>
> >> - Dan
> >>
> >> Sanjiva Weerawarana wrote:
> >>> Ummmmm. ARGH.
> >>>
> >>> Sorry Dan, scratch the mail below please. I'm on drugs. My apologies; I
> >>> see that I myself voted for it more than 72 hours ago ;-).
> >>>
> >>> Sanjiva.
> >>>
> >>> On Sat, 2006-02-25 at 06:02 +0600, Sanjiva Weerawarana wrote:
> >>>
> >>>> On Fri, 2006-02-24 at 11:36 -0500, Dan Diephouse wrote:
> >>>>
> >>>>> Did I forget to add my +1? :-) Adding it in, we have 5 +1s and no
> >>>>> -1s. I'll be doing the release this afternoon (EST) and getting
> >>>>> the website updated as well.
> >>>>>
> >>>> Um for some reason I didn't see this vote coming thru. Was it on
> >>>> commons-dev?? Hmm my filters must be screwed up.
> >>>>
> >>>> When was it called? Has it been 72 hrs since the vote? If not the vote
> >>>> is not closed and you cannot release. I know you're in a hurry but
> >>>> let's
> >>>> slow down just a little bit please :).
> >>>>
> >>>> Sanjiva.
> >>>>
> >>>
> >>>
> >>
> >>
> >
> >
>
>
> --
> Dan Diephouse
> Envoi Solutions LLC
> http://envoisolutions.com
> http://netzooid.com/blog
>
>


--
============================
Srinath Perera:
   http://www.cs.indiana.edu/~hperera/
   http://www.bloglines.com/blog/hemapani

Re: Signing Releases Re: Vote Passed [was Re: [Vote] Release XmlSchema 1.0]

Posted by Dan Diephouse <da...@envoisolutions.com>.
Just an update: I can't create a KEYS file for XmlSchema because I don't 
have write permissions to /www/www.apache.org/dist/ws.

I noticed that lots of apache releases aren't signed? Is it a 
requirement that people sign them? Does anyone actually use these 
signatures???

- Dan

Dan Diephouse wrote:
> Sorry for all the email while I try to figure out how to do releases, 
> but I'm down to one last question. Do I need to be initiated into the 
> web of trust to make releases? I created my own GPG key, signed the 
> files, then uploaded the signatures:
>
> http://www.apache.org/dist/maven-repository/org/apache/ws/commons/XmlSchema/1.0/ 
>
>
> I just can't figure out what the web of trust has to do with it...
>
> http://www.apache.org/dev/release-signing.html
>
> - Dan
>
> Dan Diephouse wrote:
>> No worries. I wasn't in a particular hurry, was just hoping to get it 
>> done sometime this weekend while I had some time. The new site is up 
>> and the release is pushed. Only thing left to do now is figure out 
>> PGP key signing. Will conquer that in a few hours then send out a 
>> release announcement!
>>
>> - Dan
>>
>> Sanjiva Weerawarana wrote:
>>> Ummmmm. ARGH.
>>>
>>> Sorry Dan, scratch the mail below please. I'm on drugs. My apologies; I
>>> see that I myself voted for it more than 72 hours ago ;-).
>>>
>>> Sanjiva.
>>>
>>> On Sat, 2006-02-25 at 06:02 +0600, Sanjiva Weerawarana wrote:
>>>  
>>>> On Fri, 2006-02-24 at 11:36 -0500, Dan Diephouse wrote:
>>>>   
>>>>> Did I forget to add my +1? :-) Adding it in, we have 5 +1s and no 
>>>>> -1s. I'll be doing the release this afternoon (EST) and getting 
>>>>> the website updated as well.
>>>>>       
>>>> Um for some reason I didn't see this vote coming thru. Was it on
>>>> commons-dev?? Hmm my filters must be screwed up.
>>>>
>>>> When was it called? Has it been 72 hrs since the vote? If not the vote
>>>> is not closed and you cannot release. I know you're in a hurry but 
>>>> let's
>>>> slow down just a little bit please :).
>>>>
>>>> Sanjiva.
>>>>     
>>>
>>>   
>>
>>
>
>


-- 
Dan Diephouse
Envoi Solutions LLC
http://envoisolutions.com
http://netzooid.com/blog