Skip to content
Select theme

JAR signing keys

Maven Central requires every published artifact to be signed with a GPG key. This runbook covers creating a key, getting it into GitHub Actions, and publishing the public half.

Terminal window
gpg --gen-key

Use these values in the interactive prompts, and choose a strong password to protect the private key (for instance with this password generator):

Real name : Federated EGA Norway
Email : fega-norway-support@elixir.no
Terminal window
gpg --list-keys
pub ed25519 2025-04-09 [SC] [expires: 2027-04-09]
A9CD638727AE6815FB12EB8FF97FCD66B6BD0F8D
uid [ultimate] FEGA Norway Team <fega-norway-support@elixir.no>
sub cv25519 2025-04-09 [E] [expires: 2027-04-09]

The hex string on the second line is the fingerprint, the key’s unique identifier. You need it for the commands below.

Gradle cannot read variables containing newlines, and an ASCII-armoured key is inherently multi-line. So the key is base64-encoded to a single line:

Terminal window
gpg --armor --export-secret-keys <fingerprint> | base64 -w 0

The result is roughly 1220 characters on one line, like LS0tLS1CRUdJTiBQ.....xPQ0stLS0tLQo=.

  1. Go to the FEGA-Norway repository → Settings
  2. Secrets and Variables → Actions
  3. Edit the SIGNING_KEY_BASE64 secret and paste the single-line key
  4. Update SIGNING_PASSWORD to match the new key’s password

Both secrets must be updated together. A mismatched pair fails the publish step with a signing error rather than anything more descriptive.

The public half lets others verify our signatures. It has to be uploaded to a public keyserver:

Terminal window
gpg --keyserver <keyserver> --send-keys <fingerprint>

The key is currently published on:

  • keyserver.ubuntu.com
  • keys.openpgp.org

Built from f91944d