Missing trust path between 2.1.12 and 2.1.13
Hi
I'm currently trying to upgrade the package on Arch Linux from 2.1.12 to 2.1.13 (cc @anatol)
While doing so, I noticed, that the release tarball for 2.1.12 has been signed by by @azat using the OpenPGP key with the fingerprint 9E3AC83A27974B84D1B3401DB86086848EF8686D, while the current 2.1.13 release tarball has been signed by @nmathewson using the OpenPGP key with the fingerprint 2133BC600AB133E1D826D173FE43009C4607B1FB.
Unfortunately, I was not able to find a cryptographic signature between those two certificates and I am not able to verify the trust path between them. This blocks us from upgrading.
I noticed, that previously, the OpenPGP key with the fingerprint B35BF85BF19489D04E28C33C21194EBB165733EA by @nmathewson has been used, which does provide a trust path to the two aforementioned keys either.
Would it be possible for you to provide third-party signatures for each other's keys, so that downstreams can validate the signatures going from one release to the next? Thank you!
Source: libevent/libevent