I'm singing my commits with my GPG key. However I'm not signing with the "main" master key but with a subkey of that GPG key. I do this so that I don't have to carry around the private key of my GPG key (the "master" key), but only the private key of the signing subkey. This way if my laptop gets stolen I can revoke the subkey only and keep the rest of my GPG key safe. So, I've uploaded the public key to BitBucket. It shows the key and even shows all the subkeys. My commits however? Unverified :(
Hi @Daan
The GPG key along with any associated subkeys that Bitbucket Cloud will validate against is the one that is stored in Personal Bitbucket Settings > Security > GPG Keys as per our documentation:
If you're certain that this matches what you have in local - there may be an issue here, as a first step I'd suggest running through the documentation above (if you have not already done so) and double checking that the keys are correct:
If there is still an issue - an investigation would require us to access your workspace directly which can only be achieved with a support ticket. Please raise a ticket, or if you encounter issues - please let me know your timezone so I may raise one on your behalf with the team operating in your region (as per your Premium support entitlement):
Cheers!
- Ben (Bitbucket Cloud Support)
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.