I've started to sign release tarballs:
http://libguestfs.org/download/1.21-development/
The *.tar.gz.sig file is a PGP ASCII-armored signature of the
corresponding *.tar.gz file. It is signed using gpg2 with this key:
pub 4096R/E1B768A0 2011-10-11
Key fingerprint = F777 4FB1 AD07 4A7E 8C87 67EA 9173 8F73 E1B7 68A0
uid Richard W.M. Jones <rjones(a)redhat.com>
uid Richard W.M. Jones <rich(a)annexia.org>
sub 4096R/2D07308A 2011-10-11
I've only signed the two latest releases so far. I will go back and
sign the rest of the tarballs, but will wait for people here to
confirm that the signatures look good.
Rich.
--
Richard Jones, Virtualization Group, Red Hat
http://people.redhat.com/~rjones
virt-p2v converts physical machines to virtual machines. Boot with a
live CD or over the network (PXE) and turn machines into KVM guests.
http://libguestfs.org/virt-v2v