Hi all!
I noted this morning that since 2026-09-09 apt.releases.hashicorp com has a new signing key in use and I would like confirmation that it is genuine before we roll it out to our fleet.
apt.releases.hashicorp com/gpg now serves key FC9CA96ACA026560,
fingerprint D55C 0D1A C78A 8D81 26CB 631C FC9C A96A CA02 6560, created
2026-09-09. The noble and jammy InRelease files were re-signed with it on
2026-09-10, and apt.releases.hashicorp com lists the new fingerprint.
Plus, I noted that https://www.hashicorp.com/en/trust/security still lists the Linux package
signing key as 798A EC65 4E5C 1542 8C8E 42EE AA16 FCBC A621 E701 and does
not mention the new one.
I wasn’t able to find any announcement or news on this, can you share it if there’s one?
Can you confirm the new key is legitimate?
Thanks
Silvia
Lead SRE @37signals