Title: Requesting access to the code signing service license: https://www.apache.org/licenses/LICENSE-2.0
The ASF currently uses ssl.com's eSigner to sign JARs and Windows executables.
To gain access to the service, create a Jira ticket with the following information:
code signingThe infra team will then request the account creation and (after a few e-mails and configuring a OTP token) you will have an account that lets you access the service. Each PMC member must have their own account to access the service.
Release managers can then sign release artifacts via:
For the first three options, the code signing is performed locally (no need to upload large files, just the hashes are passed to the central signing service).