gnutls 3.7.8 tarball signed with different key than announced
Description of problem:
When attempting to verify the tarball signature, key A6AB53A01D237A94F9EEC4D0412748A40AFCC2FB is found with not match to the gnutls keyring. This also differs from the email announcement, stating key E987AB7F7E89667776D05B3BB0E9DD20B29F1432 was used. Other two keys used match the keyring
Version of gnutls used:
3.7.8
Distributor of gnutls (e.g., Ubuntu, Fedora, RHEL)
Gnutls direct download
How reproducible:
download 3.7.8 tarball and sig. Open Kleopatra and verify tarball.
Actual results:
Signatures found are: 5D46CB0F763405A7053556F47A75A648B3F9220C 462225C3B46F34879FC8496CD605848ED7E69871 A6AB53A01D237A94F9EEC4D0412748A40AFCC2FB Last one is not present in gnutls keyring located at https://www.gnutls.org/gnutls-release-keyring.gpg
Expected results:
Signatures found should be(according to 9/27 announcement): 5D46CB0F763405A7053556F47A75A648B3F9220C 462225C3B46F34879FC8496CD605848ED7E69871 E987AB7F7E89667776D05B3BB0E9DD20B29F1432 These three are all present in the keyring