Two keys, two roles

OpenPGP Keys

Public keys of Saturneric · eric@bktus.com

Which key is which

There are two keys, and they are deliberately kept apart. One signs code and binaries and is never used for mail. The other is used for email only and is never used to sign a release.

Both carry the same eric@bktus.com address in their user ID, so an address alone does not identify a key. Always select and verify by fingerprint.

Code & binary signing

Used only to sign source releases, commits, tags, and binary artifacts. Never used for email.

User ID
saturneric (for code or binary sign only) <eric@bktus.com>
Fingerprint
12F7 E885 8CF1 5BEC 9975 FF3C 5CA3 DA24 6843 FD03
Key ID
5CA3DA246843FD03
Algorithm
ed25519
Capabilities
sign, certify, authenticate
Created
2024-08-17
Valid until
2028-08-17
-----BEGIN PGP PUBLIC KEY BLOCK-----

mDMEZsEF1xYJKwYBBAHaRw8BAQdAPZ3dA2od9HFaiaJRr1TEEeRMfAcrBp8oqQPa
R16Icva0OHNhdHVybmVyaWMoZm9yIGNvZGUgb3IgYmluYXJ5IHNpZ24gb25seSk8
ZXJpY0Bia3R1cy5jb20+iJkEExYKAEECGyMFCwkIBwICIgIGFQoJCAsCBBYCAwEC
HgcCF4AWIQQS9+iFjPFb7Jl1/zxco9okaEP9AwUCak/5lAUJB4YCzQAKCRBco9ok
aEP9A2XlAP9oSRnrx/FoWrrb1ykaN91+gU2lCI89sP+0b6xjsPVR/gD+ILOYmW0N
97/LfmFW9t+kxvsTpoblvwS2is7DeTt3vg8=
=7fLZ
-----END PGP PUBLIC KEY BLOCK-----
Email

Used only for email: signing messages sent from eric@bktus.com, and receiving encrypted mail. Never used to sign code.

User ID
saturneric (for email only) <eric@bktus.com>
Fingerprint
6F28 02C9 9966 27E3 C399 017C 5891 8736 9966 F02B
Key ID
589187369966F02B
Algorithm
ed25519
Capabilities
sign, certify, authenticate
Created
2024-08-03
Valid until
2028-08-03
Subkey · encrypt
Fingerprint
84FB 7353 8973 7911 2EBF 711C E5B2 8C9B 8960 3C4D
Algorithm
cv25519
Created
2024-08-03
Valid until
2028-08-14
-----BEGIN PGP PUBLIC KEY BLOCK-----

mDMEZq5pTxYJKwYBBAHaRw8BAQdA+YEVawOeMQaAPI4rMfycgbDKA7ebPJ0V2r2J
+HPKbz60KnNhdHVybmVyaWMoZm9yIGVtYWlsIG9ubHkpPGVyaWNAYmt0dXMuY29t
PoiZBBMWCgBBAhsjBQsJCAcCAiICBhUKCQgLAgQWAgMBAh4HAheAFiEEbygCyZlm
J+PDmQF8WJGHNplm8CsFAmpP+gwFCQeGAykACgkQWJGHNplm8Ct8HAD/bRdPvCWL
/qeI9e4RUiEfqumEvzVnLLsi97O1olReH7YA/Ao2f4rGK/Covk4wx+nKlHtozP6E
mLJYmKVSBwhfz1IGuDgEZq5pbxIKKwYBBAGXVQEFAQEHQB5fS+kyqWm+7JvVRIL8
7hzP4Zi1WdQ85Tkr7JbfEOxFAwEIB4h+BBgWCgAmAhsMFiEEbygCyZlmJ+PDmQF8
WJGHNplm8CsFAmp/U9YFCQeUouUACgkQWJGHNplm8Ct8pwD/bcXSwTApPH/6tAdX
8BrwbynWYBj5iHT8ZMamBs/woVIA/R0Yi6FBIaXAjFZQuJx8qCu9rHM0VSS6yE+Z
IKLNFxQA
=PCaW
-----END PGP PUBLIC KEY BLOCK-----
Private key storage

The devices that store these private keys do not leave Germany.

The keys are not copied to, backed up to, or used from any system outside the country.

Fetching and verifying

The email key is published over Web Key Directory, so GnuPG can find it on its own. The code signing key is not, so that a mail client never picks it up by address:

gpg --locate-keys eric@bktus.com

Or fetch either key directly from this site:

curl -sS https://bktus.com/pgp/saturneric-code-signing.asc | gpg --import
curl -sS https://bktus.com/pgp/saturneric-email.asc | gpg --import

After importing, compare the fingerprint that gpg prints against the one listed above, and against at least one source other than this page:

gpg --fingerprint 5CA3DA246843FD03
gpg --fingerprint 589187369966F02B

A fingerprint read from the same page that served the key proves very little on its own. Confirm it through a channel that does not depend on this server.

Contact