PageSourceSearch

https://www.rabbitmq.com/assets/js/6bebabae.b0ff9c39.js

js rabbitmq.com collected 2026-09-24 06:05:41 UTC 11,242 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkrabbitmq_website=self.webpackChunkrabbitmq_website||[]).push([["15974"],{98241(e,n,i){i.r(n),i.d(n,{metadata:()=>s,default:()=>c,frontMatter:()=>t,contentTitle:()=>d,toc:()=>l,assets:()=>g});var s=JSON.parse('{"id":"signatures","title":"Package Signatures","description":"\x3c!--","source":"@site/versioned_docs/version-3.13/signatures.md","sourceDirName":".","slug":"/signatures","permalink":"/docs/3.13/signatures","draft":false,"unlisted":false,"editUrl":"https://github.com/rabbitmq/rabbitmq-website/tree/main/versioned_docs/version-3.13/signatures.md","tags":[],"version":"3.13","frontMatter":{"title":"Package Signatures","displayed_sidebar":"docsSidebar"},"sidebar":"docsSidebar","previous":{"title":"Erlang Version Requirements","permalink":"/docs/3.13/which-erlang"},"next":{"title":"Supported Platforms","permalink":"/docs/3.13/platforms"}}'),r=i(74848),a=i(28453);let t={title:"Package Signatures",displayed_sidebar:"docsSidebar"},d="Package Signatures",g={},l=[{value:"Overview",id:"overview",level:2},{value:"Signing Keys",id:"signing-keys",level:2},{value:"Importing Signing Keys",id:"importing-gpg-keys",level:2},{value:"With GPG",id:"importing-gpg",level:3},{value:"Direct Download",id:"direct-download",level:4},{value:"Using a Key Server",id:"using-a-key-server",level:4},{value:"With apt",id:"importing-apt",level:3},{value:"Direct Download",id:"direct-download-1",level:4},{value:"Using a Key Server",id:"using-a-key-server-1",level:4},{value:"With RPM",id:"importing-rpm",level:3},{value:"Direct Download",id:"direct-download-2",level:4},{value:"Verifying Signatures",id:"checking-signatures",level:2}];function o(e){let n={a:"a",code:"code",h1:"h1",h2:"h2",h3:"h3",h4:"h4",header:"header",p:"p",pre:"pre",...(0,a.R)(),...e.components};return(0,r.jsxs)(r.Fragment,{children:[(0,r.jsx)(n.header,{children:(0,r.jsx)(n.h1,{id:"package-signatures",children:"Package Signatures"})}),"\n",(0,r.jsx)(n.h2,{id:"overview",children:"Overview"}),"\n",(0,r.jsx)(n.p,{children:"This guide covers RabbitMQ release packages signing and how to verify the signatures on\ndownloaded release artifacts."}),"\n",(0,r.jsxs)(n.p,{children:["Release signing allows users to verify that the artifacts they have downloaded\nwere published by a trusted party (such as a team or package distribution\nservice). This can be done using GPG command line tools. Package management tools such as ",(0,r.jsx)(n.code,{children:"apt"})," and ",(0,r.jsx)(n.code,{children:"yum"}),"\nalso verify repository signatures."]}),"\n",(0,r.jsx)(n.h2,{id:"signing-keys",children:"Signing Keys"}),"\n",(0,r.jsxs)(n.p,{children:["RabbitMQ release artifacts, both binary and source,\nare signed using ",(0,r.jsx)(n.a,{href:"http://www.gnupg.org/",children:"GnuPG"})," and ",(0,r.jsx)(n.a,{href:"https://github.com/rabbitmq/signing-keys/releases/download/3.0/rabbitmq-release-signing-key.asc",children:"our release signing key"}),"."]}),"\n",(0,r.jsxs)(n.p,{children:["In addition, the contents of the ",(0,r.jsx)(n.a,{href:"./install-debian/",children:"Debian"})," repositories maintained by Team RabbitMQ\nare signed using the same key."]}),"\n",(0,r.jsx)(n.h2,{id:"importing-gpg-keys",children:"Importing Signing Keys"}),"\n",(0,r.jsx)(n.h3,{id:"importing-gpg",children:"With GPG"}),"\n",(0,r.jsxs)(n.p,{children:["Before signatures can be verified, RabbitMQ ",(0,r.jsx)(n.a,{href:"https://github.com/rabbitmq/signing-keys/releases/download/3.0/rabbitmq-release-signing-key.asc",children:"signing key"}),"\nmust be downloaded. The key can be obtained directly or using ",(0,r.jsx)(n.a,{href:"https://keys.openpgp.org/",children:"keys.openpgp.org"}),".\nThe direct download method is recommended because most key servers are prone to overload, abuse and attacks."]}),"\n",(0,r.jsx)(n.h4,{id:"direct-download",children:"Direct Download"}),"\n",(0,r.jsxs)(n.p,{children:["The key is distributed via ",(0,r.jsx)(n.a,{href:"https://github.com/rabbitmq/signing-keys/releases/",children:"GitHub"})," and\n",(0,r.jsx)(n.a,{href:"https://www.rabbitmq.com/rabbitmq-release-signing-key.asc",children:"rabbitmq.com"}),":"]}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{className:"language-bash",children:"curl -L https://github.com/rabbitmq/signing-keys/releases/download/3.0/rabbitmq-release-signing-key.asc --output rabbitmq-release-signing-key.asc\ngpg --import rabbitmq-release-signing-key.asc\n"})}),"\n",(0,r.jsx)(n.h4,{id:"using-a-key-server",children:"Using a Key Server"}),"\n",(0,r.jsxs)(n.p,{children:["The key can be imported from ",(0,r.jsx)(n.a,{href:"https://keys.openpgp.org/",children:"keys.openpgp.org"}),":"]}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{className:"language-bash",children:'gpg --keyserver "hkps://keys.openpgp.org" --recv-keys "0x0A9AF2115F4687BD29803A206B73A36E6026DFCA"\n'})}),"\n",(0,r.jsx)(n.p,{children:"Alternative keyservers:"}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{className:"language-bash",children:'gpg --keyserver "keyserver.ubuntu.com" --recv-keys "0x0A9AF2115F4687BD29803A206B73A36E6026DFCA"\n'})}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{className:"language-bash",children:'gpg --keyserver "pgp.surfnet.nl" --recv-keys "0x0A9AF2115F4687BD29803A206B73A36E6026DFCA"\n'})}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{className:"language-bash",children:'gpg --keyserver "pgp.mit.edu" --recv-keys "0x0A9AF2115F4687BD29803A206B73A36E6026DFCA"\n'})}),"\n",(0,r.jsx)(n.h3,{id:"importing-apt",children:"With apt"}),"\n",(0,r.jsxs)(n.p,{children:["On Debian and Ubuntu systems, assuming that ",(0,r.jsx)(n.a,{href:"./install-debian",children:"apt repositories"})," are used for installation,\ntrusted repository signing keys must be added to the system before any packages can be installed."]}),"\n",(0,r.jsx)(n.p,{children:"This can be done using key servers or (for the RabbitMQ main signing key) a direct download."}),"\n",(0,r.jsx)(n.h4,{id:"direct-download-1",children:"Direct Download"}),"\n",(0,r.jsxs)(n.p,{children:["Main RabbitMQ signing key is distributed via ",(0,r.jsx)(n.a,{href:"https://github.com/rabbitmq/signing-keys/releases/",children:"GitHub"})," and\n",(0,r.jsx)(n.a,{href:"https://www.rabbitmq.com/rabbitmq-release-signing-key.asc",children:"rabbitmq.com"}),":"]}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{className:"language-bash",children:"curl -1sLf https://github.com/rabbitmq/signing-keys/releases/download/3.0/rabbitmq-release-signing-key.asc | sudo gpg --dearmor > /usr/share/keyrings/com.rabbitmq.team.gpg\n"})}),"\n",(0,r.jsx)(n.h4,{id:"using-a-key-server-1",children:"Using a Key Server"}),"\n",(0,r.jsxs)(n.p,{children:["The same main RabbitMQ signing key can be imported from ",(0,r.jsx)(n.a,{href:"https://keys.openpgp.org/",children:"keys.openpgp.org"}),":"]}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{className:"language-bash",children:'curl -1sLf "https://keys.openpgp.org/vks/v1/by-fingerprint/0A9AF2115F4687BD29803A206B73A36E6026DFCA" | sudo gpg --dearmor > /usr/share/keyrings/com.rabbitmq.team.gpg\n'})}),"\n",(0,r.jsxs)(n.p,{children:["When using the ",(0,r.jsx)(n.a,{href:"https://launchpad.net/~rabbitmq/+archive/ubuntu/rabbitmq-erlang",children:"Team RabbitMQ modern Erlang PPA"}),",\none more key needs to be added:"]}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{className:"language-bash",children:'## Team RabbitMQ\'s signing key\ncurl -1sLf "https://keys.openpgp.org/vks/v1/by-fingerprint/0A9AF2115F4687BD29803A206B73A36E6026DFCA" | sudo gpg --dearmor > /usr/share/keyrings/com.rabbitmq.team.gpg\n'})}),"\n",(0,r.jsx)(n.h3,{id:"importing-rpm",children:"With RPM"}),"\n",(0,r.jsxs)(n.p,{children:["On RPM-based systems (RHEL, Fedora, CentOS), assuming that ",(0,r.jsx)(n.a,{href:"./install-rpm",children:"yum repositories"})," are used for installation,\n",(0,r.jsx)(n.code,{children:"rpm --import"})," should be used to import the key."]}),"\n",(0,r.jsx)(n.h4,{id:"direct-download-2",children:"Direct Download"}),"\n",(0,r.jsxs)(n.p,{children:["The key is distributed via ",(0,r.jsx)(n.a,{href:"https://github.com/rabbitmq/signing-keys/releases/",children:"GitHub"})," and\n",(0,r.jsx)(n.a,{href:"https://www.rabbitmq.com/rabbitmq-release-signing-key.asc",children:"rabbitmq.com"}),":"]}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{className:"language-bash",children:"rpm --import https://github.com/rabbitmq/signing-keys/releases/download/3.0/rabbitmq-release-signing-key.asc\n"})}),"\n",(0,r.jsx)(n.h2,{id:"checking-signatures",children:"Verifying Signatures"}
1),"\n",(0,r.jsxs)(n.p,{children:["To check signatures for the packages, download the RabbitMQ signing key\nand a signature file. Signature files use the ",(0,r.jsx)(n.code,{children:".asc"})," extension that follows their artifact filename,\ne.g. the signature file of ",(0,r.jsx)(n.code,{children:"rabbitmq-server-generic-unix-4.0.4.tar.xz"})," would be ",(0,r.jsx)(n.code,{children:"rabbitmq-server-generic-unix-4.0.4.tar.xz.asc"}),"."]}),"\n",(0,r.jsxs)(n.p,{children:["Then use ",(0,r.jsx)(n.code,{children:"gpg --verify"}),":"]}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{className:"language-bash",children:"gpg --verify [filename].asc [filename]\n"})}),"\n",(0,r.jsx)(n.p,{children:"Here's an example session, after having retrieved a RabbitMQ\nsource archive and its associated detached signature from\nthe download area:"}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{className:"language-bash",children:'gpg --verify rabbitmq-server_4.1.4-1_all.deb.asc rabbitmq-server_4.1.4-1_all.deb\n# => gpg: Signature made (date elided)\n# => gpg:                using RSA key 0A9AF2115F4687BD29803A206B73A36E6026DFCA\n# => gpg: Good signature from "RabbitMQ Release Signing Key <[email protected]>" [unknown]\n# (elided)\n# => Primary key fingerprint: 0A9A F211 5F46 87BD 2980  3A20 6B73 A36E 6026 DFCA\n'})}),"\n",(0,r.jsx)(n.p,{children:'If the signature is invalid, a "BAD signature"\nmessage will be emitted. If that\'s the case the origin of the package,\nthe signature file and the signing key should be carefully verified.\nPackages that fail signature verification must not be used.'}),"\n",(0,r.jsx)(n.p,{children:'If the signature is valid, you should expect a "Good\nsignature" message; if you\'ve not signed our key, you will\nsee a "Good signature" message along with a warning about\nour key being untrusted.'}),"\n",(0,r.jsxs)(n.p,{children:["If you trust the RabbitMQ signing key you avoid the warning output by\nGnuPG by signing it using your own key (to create your private key run ",(0,r.jsx)(n.code,{children:"gpg --gen-key"}),"):"]}),"\n",(0,r.jsx)(n.pre,{children:(0,r.jsx)(n.code,{className:"language-bash",children:"gpg --sign-key 0x0A9AF2115F4687BD29803A206B73A36E6026DFCA\n"})})]})}function c(e={}){let{wrapper:n}={...(0,a.R)(),...e.components};return n?(0,r.jsx)(n,{...e,children:(0,r.jsx)(o,{...e})}):o(e)}},28453(e,n,i){i.d(n,{R:()=>t,x:()=>d});var s=i(96540);let r={},a=s.createContext(r);function t(e){let n=s.useContext(a);return s.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function d(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(r):e.components||r:t(e.components),s.createElement(a.Provider,{value:n},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.