/// Trust, but check the fingerprint

Verify us before you trust us.

Anyone can send email claiming to be a CSIRT. Our advisories are signed, and reports to us can be encrypted, with the key below.

PRIMARY KEY — FINGERPRINT✓ PUBLISHED
684C 7B7D A77E 4F1B 68AE
D3EC E84B 541C 6184 CC6F
TYPE   RSA 4096
UID    GARNET CSIRT <csirt@garnet.edu.gh>
CREATED  2026-08-04
EXPIRES  2028-08-03

§ Verification

Three commands

Import, check the fingerprint against the block on the left, then verify the signature on any advisory you receive.

$ gpg --import garnet-csirt.asc
$ gpg --fingerprint csirt@garnet.edu.gh
$ gpg --verify 2026-001-openssh-regresshion.md.asc 2026-001-openssh-regresshion.md

Every advisory links its own .md and detached.md.asc — the “Verify this advisory” box on each page has the exact two-file command.

If the fingerprint printed by gpg differs from the one shown here by even one character, stop and call us on 0208 110 248.

§ Team identity

RFC 2350 summary

The short form of our team description. The full document is available as a signed PDF.

Official name

GARNET CSIRT — Computer Security Incident Response Team of the Ghanaian Academic and Research Network

Constituency

GARNET member institutions and the network infrastructure they operate under GARNET address space.

Authority

Coordinating, not enforcing. Members retain full authority over their own systems and decisions.

Disclosure

Reports are handled confidentially. Nothing identifying a member is shared without that member’s consent.