Description
We currently have the private / public key pair we use for our builds in the repository. This means that the signature on our NuGets and DLLs is not trustworthy. We should find a way to produce properly signed NuGets.
Note: None of this affects the official source release, nor the signature on the Java Maven artifacts. Both are signed with GnuPG, using a key we keep private.
Attachments
Issue Links
- blocks
-
REEF-572 Release 0.13
- Resolved
- is related to
-
REEF-457 Strong-name signed assemblies must specify a public key in their InternalsVisibleTo declarations
- Resolved
-
REEF-458 Remove key pair snk file from repository, regenerate the key and push public key
- Resolved
- relates to
-
REEF-713 revert public key that should matche the keyfile.snk
- Resolved