For nm.debian.org, at 2021-01-21:
For the past two years, I have worked with Glenn Strauss on lighttpd.
Glenn is the primary upstream author of lighttpd. He signed all recent upstream
releases with a different key whose fingerprint is:
649D 0DD7 67FF 2062 02A7 6C51 58F1 4A78 6FE1 98C8
I've verified those signatures for all uploads that I made to Debian in the
With the abovementioned upstream key, Glenn sent me a signed transition
statement endorsing his new key for Debian:
8EC0 3CE5 78AA CDD4 0356 AEE2 CCF9 03D8 6BBE ED0C
I've made sure that he is able to decrypt encrypted messages sent to this key
and that he is able to sign messages with the same key.
Due to the interactions during the past two years we had, I'm convinced that
Glenn Strauss as he presents himself on nm.debian.org is the rightful owner of
both email firstname.lastname@example.org (the one on the key, not
email@example.com, but it seems like Glenn is in control of the whole
domain and uses local parts for sorting), GPG key 649D 0DD7 67FF 2062 02A7 6C51
58F1 4A78 6FE1 98C8. Due to the signed transition statement, I'm also convinced
that he is the rightful owner of GPG key 8EC0 3CE5 78AA CDD4 0356 AEE2 CCF9
03D8 6BBE ED0C.