This page contains information on the current and past archive signing keys. The release files are signed by an automatic archive signing key in order to allow verification that software being downloaded has not been interfered with.
Please note that the details here are for information only, you should not rely on them and use other ways to verify them.
Which release should be signed with which key?
Stable releases are signed by both the ftp-master automatic archive signing key in use at the time of the release, and a per-release stable key. Release files for other releases (proposed-updates, testing, testing-proposed-updates, unstable and experimental) are signed only by the ftp-master automatic key.
The security archive is signed by the ftp-master key only.
The current procedure is that there is one ftp-master key per release (former procedure introduced a new key once per year).
Active Signing Keys
The current (2010/squeeze) key can be downloaded here
The fingerprint of this key is 9FED 2BCB DCD2 9CDF 7626 78CB AED4 B06F 4730 41FA.
The announcement regarding this key can be read at https://lists.debian.org/debian-devel-announce/2010/08/msg00006.html and https://www.debian.org/News/2011/20110209.
The new (2012/wheezy) key can be downloaded here
The fingerprint of this key is A1BD 8E9D 78F7 FE5C 3E65 D8AF 8B48 AD62 4692 5553.
The announcement regarding this key can be read at https://lists.debian.org/debian-devel-announce/2012/05/msg00000.html.
The fingerprint of the squeeze stable release key is 0E4E DE2C 7F3E 1FC0 D033 800E 6448 1591 B983 21F9
The fingerprint of the wheezy stable release key is ED6D 6527 1AAC F0FF 15D1 2303 6FB2 A1C2 65FF B764
Retired Signing Keys
The following retired and in most cases expired keys are available. Note that these keys are no longer in use and are listed here for reference purposes only:
Key Replacement Procedure
When the archive key is to be replaced, a new key will be generated by one of the ftpmasters. This key will then be signed by that ftpmaster and other ftpmasters and members of the ftpteam (including verification by phone call of the fingerprint and other details of the key to be signed).
Once the new key is prepared, it will be placed on this page, put into the relevant archive packages and announced to debian-devel-announce well in advance of being used.
Key Revocation Procedure
A revokation certificate for the archive key is produced at the time of the creation of an archive key. The program gfshare (package libgfshare-bin) (a Shamir's secret sharing scheme implementation) is then used to produce 12 shares of which 7 are needed to recover the revokation cert. This procedure is for use in emergencies only (such as losing ftp-master.debian.org and all of the backups, a hopefully unlikely event) as the key can normally be used to produce its own revokation certificate.
Key Backup / Restore Procedure
After the creation of the archive key, the secret part of it will be backed up in one additional way. The program gfshare (package libgfshare-bin) (a Shamir's secret sharing scheme implementation) is used to produce 14 shares of which 9 are needed to recover the secret key.
The following people each hold one of the shares of the revocation certificate / private key.
7 of those shares are needed to reproduce the revocation certificate
9 of those shares are needed to reproduce the secret key
Debian FTP team