Rootwire Ltd - OpenPGP key publication

This domain publishes the OpenPGP signing keys used by Rootwire Ltd for evidence sealing and document signing in incident response and consultancy engagements. Keys are served via Web Key Directory (WKD) and mirrored on keys.openpgp.org.

Current evidence-signing key

Aiden Arnkels-Webb (Rootwire Ltd evidence signing)
aiden@rootwire.com

Fingerprint:
2CE8 2BB2 8472 64D3 8EFC EF1A 0C73 DA52 6BE3 A986

The private key was generated on, and is non-exportable from, a hardware security token. Every signature requires the physical token, a PIN, and a physical touch confirmation.

Fetching the key

gpg --locate-keys aiden@rootwire.com

or from the keyserver:

gpg --keyserver keys.openpgp.org --recv-keys <fingerprint>

Verifying a Rootwire evidence manifest

gpg --verify MANIFEST-<timestamp>.sha256.asc MANIFEST-<timestamp>.sha256

A valid signature from the fingerprint above confirms the manifest was signed with Rootwire's hardware token. Manifests are additionally timestamped by an independent RFC 3161 trusted timestamping authority (.tsr file alongside each manifest).

Provenance

This site is published from a public Git repository; its commit history provides an independent record of when each key was first published and any subsequent changes: github.com/aidenwebb/openpgpkey-site-rootwire-com.