Company
Date Published
Author
Company
Word count
900
Language
-
Hacker News points
None

Summary

InfluxData is undergoing a package signing key rotation process due to the current key's expiration in January 2026, having previously updated its approach in 2023 to use a primary key with signing subkeys for a smoother transition. This method allows the public key to be updated with a new signing subkey without altering the primary key's fingerprint, providing continuity and ease for users. The rotation involves stages, including documentation updates, generating new signing subkeys, and creating a new Linux package, "influxdata-archive-keyring," which configures systems for seamless updates. Users are advised to verify their system configurations, ensuring they're using the correct keys to avoid disruption. RPM and DEB installations will incorporate these changes, and users are encouraged to update configurations to align with these updates, verifying key fingerprints to maintain cryptographic integrity. The communication and rollout strategy aims to minimize disruption, with users urged to adhere to recommended practices for a smooth transition.