diff --git a/README.md b/README.md index 23e3338..0e76317 100644 --- a/README.md +++ b/README.md @@ -108,7 +108,7 @@ The GnuPG public key used to sign the current and new releases is available in You can verify it against Taylor Hornby's [contact page](https://defuse.ca/contact.htm) and -[twitter](https://twitter.com/DefuseSec/status/723741424253059074). +[twitter](https://twitter.com/DefuseSec/status/1670840796743081984). Older releases were signed with a (now-expired) available in [dist/signingkey-old.asc](https://github.com/defuse/php-encryption/raw/master/dist/signingkey-old.asc). The old key's fingerprint is: @@ -117,5 +117,8 @@ Older releases were signed with a (now-expired) available in 2FA6 1D8D 99B9 2658 6BAC 3D53 385E E055 A129 1538 ``` +The old key's fingerprint can be verified against Taylor Hornby's [contact page](https://defuse.ca/contact.htm) and +[twitter](https://twitter.com/DefuseSec/status/723741424253059074). + A signature of this new key by the old key is available in [dist/signingkey-new.asc.sig](https://github.com/defuse/php-encryption/raw/master/dist/signingkey-new.asc.sig).