# Maven Deploy validation failed: Invalid signature for file

**URL:** <https://community.sonatype.com/t/maven-deploy-validation-failed-invalid-signature-for-file/12023>\
**Category:** Central Repository\
**Created:** [February 6, 2024, 1:49pm UTC](https://community.sonatype.com/t/maven-deploy-validation-failed-invalid-signature-for-file/12023 "2024-02-06T13:49:26Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![brenoepics](https://avatars.discourse-cdn.com/v4/letter/b/3ab097/32.png) [@brenoepics](https://community.sonatype.com/u/brenoepics)\
**Post date:** [February 6, 2024, 1:49pm UTC](https://community.sonatype.com/t/maven-deploy-validation-failed-invalid-signature-for-file/12023/1 "2024-02-06T13:49:26Z")

</div>

![image](https://canada1.discourse-cdn.com/flex047/uploads/communitysonatype/original/2X/5/5f8d955333d1031382a4f048bad723e1ab98256a.png)  
I tried to validate in other places and it works, because I didn’t change anything other than updating to 0.3.0 of the central-publishing-maven-plugin (previous versions receive a 500 error from sonatype)

My pom.xml is here → [at4j - Pastebin.com](https://pastebin.com/ceuW22rh)

---

<div class="post-metadata">

**Author:** ![brenoepics](https://avatars.discourse-cdn.com/v4/letter/b/3ab097/32.png) [@brenoepics](https://community.sonatype.com/u/brenoepics)\
**Post date:** [February 6, 2024, 1:50pm UTC](https://community.sonatype.com/t/maven-deploy-validation-failed-invalid-signature-for-file/12023/2 "2024-02-06T13:50:00Z")

</div>

![image](https://canada1.discourse-cdn.com/flex047/uploads/communitysonatype/original/2X/8/8de4185e85ff4df0d142bf8b0ae0aceac7e498e1.png)

Central-Build → [central-bundle](https://www.mediafire.com/file/4yfr0d524efnebr/central-bundle.zip/file)

---

<div class="post-metadata">

**Author:** ![cantaylancapraz](https://avatars.discourse-cdn.com/v4/letter/c/a4c791/32.png) [@cantaylancapraz](https://community.sonatype.com/u/cantaylancapraz)\
**Post date:** [February 8, 2024, 7:13pm UTC](https://community.sonatype.com/t/maven-deploy-validation-failed-invalid-signature-for-file/12023/3 "2024-02-08T19:13:01Z")

</div>

Did you solve this?

---

<div class="post-metadata">

**Author:** ![brenoepics](https://avatars.discourse-cdn.com/v4/letter/b/3ab097/32.png) [@brenoepics](https://community.sonatype.com/u/brenoepics)\
**Post date:** [February 9, 2024, 2:33am UTC](https://community.sonatype.com/t/maven-deploy-validation-failed-invalid-signature-for-file/12023/4 "2024-02-09T02:33:43Z")

</div>

Yeah, I had to add

```java
plugin...
<executions>
                    <execution>
                        <id>attach-javadocs</id>
                        <phase>package</phase> <---this
                        <goals>
                            <goal>jar</goal>
                        </goals>
                    </execution>
</executions>

```

To all of them

---

<div class="post-metadata">

**Author:** ![saitejanaiduthota](https://avatars.discourse-cdn.com/v4/letter/s/a3d4f5/32.png) [@saitejanaiduthota](https://community.sonatype.com/u/saitejanaiduthota)\
**Post date:** [March 24, 2024, 5:07pm UTC](https://community.sonatype.com/t/maven-deploy-validation-failed-invalid-signature-for-file/12023/6 "2024-03-24T17:07:24Z")

</div>

Hi Breno ,  
i tried doing the same and i am still facing the same issue since 5 days . can you kindly help me on this.  
this is my pom.xml

\<?xml version="1.0" encoding="UTF-8"?\>

4.0.0

```
<parent>
    <groupId>org.springframework.boot</groupId>
    <artifactId>spring-boot-starter-parent</artifactId>
    <version>3.2.0</version>
    <relativePath/> <!-- lookup parent from repository -->
</parent>

<groupId>io.github.bughunter98</groupId>
<artifactId>blog-integrations</artifactId>
<version>1.0.0</version>

<name>blog-integrations</name>
<description>This is a light-weight jar used where all the pojos required for my project are stored</description>
<url>https://github.com/bughunter98/blogapp-integrations</url>

<licenses>
    <license>
        <name>Apache License 2.0</name>
        <url>https://github.com/bughunter98/blogapp-integrations/blob/release-1.0.0/LICENSE</url>
    </license>
</licenses>

<properties>
    <maven.compiler.source>11</maven.compiler.source>
    <maven.compiler.target>11</maven.compiler.target>
    <maven-compiler-plugin.version>3.11.0</maven-compiler-plugin.version>
    <java.version>17</java.version>
    <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
    <central-publishing-maven-plugin.version>0.3.0</central-publishing-maven-plugin.version>
    <nexus-staging-maven-plugin.version>1.6.7</nexus-staging-maven-plugin.version>
    <maven-javadoc-plugin.version>3.6.3</maven-javadoc-plugin.version>
</properties>

<dependencies>
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-web</artifactId>
    </dependency>
    <dependency>
        <groupId>org.modelmapper</groupId>
        <artifactId>modelmapper</artifactId>
        <version>3.2.0</version>
    </dependency>
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-webflux</artifactId>
    </dependency>

    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-devtools</artifactId>
        <scope>runtime</scope>
        <optional>true</optional>
    </dependency>
    <dependency>
        <groupId>com.mysql</groupId>
        <artifactId>mysql-connector-j</artifactId>
        <version>8.2.0</version>
    </dependency>
    <dependency>
        <groupId>org.projectlombok</groupId>
        <artifactId>lombok</artifactId>
        <optional>true</optional>
    </dependency>
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-data-jpa</artifactId>
    </dependency>
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-test</artifactId>
        <scope>compile</scope>
    </dependency>
    <dependency>
        <groupId>io.projectreactor</groupId>
        <artifactId>reactor-test</artifactId>
        <scope>compile</scope>
    </dependency>
    <!-- https://mvnrepository.com/artifact/org.springframework.boot/spring-boot-starter-validation -->
    <dependency>
        <groupId>org.springframework.boot</groupId>
        <artifactId>spring-boot-starter-validation</artifactId>
    </dependency>
    <dependency>
        <groupId>io.jsonwebtoken</groupId>
        <artifactId>jjwt-jackson</artifactId>
        <version>0.11.5</version>
    </dependency>
    <dependency>
        <groupId>io.jsonwebtoken</groupId>
        <artifactId>jjwt-api</artifactId>
        <version>0.11.5</version>
    </dependency>
    <dependency>
        <groupId>io.jsonwebtoken</groupId>
        <artifactId>jjwt-impl</artifactId>
        <version>0.11.5</version>
    </dependency>
</dependencies>

<build>
    <plugins>
        <plugin>
            <groupId>org.apache.maven.plugins</groupId>
            <artifactId>maven-compiler-plugin</artifactId>
            <version>${maven-compiler-plugin.version}</version>
            <configuration>
                <source>${java.version}</source>
                <target>${java.version}</target>
            </configuration>
        </plugin>
        <plugin>
            <groupId>org.sonatype.central</groupId>
            <artifactId>central-publishing-maven-plugin</artifactId>
            <version>${central-publishing-maven-plugin.version}</version>
            <extensions>true</extensions>
            <configuration>
                <publishingServerId>central</publishingServerId>
                <tokenAuth>true</tokenAuth>
            </configuration>
        </plugin>
        <plugin>
            <groupId>org.apache.maven.plugins</groupId>
            <artifactId>maven-source-plugin</artifactId>
            <version>3.3.0</version>
            <executions>
                <execution>
                    <id>attach-sources</id>
                    <phase>package</phase>
                    <goals>
                        <goal>jar</goal>
                    </goals>
                </execution>
            </executions>
        </plugin>
        <plugin>
            <groupId>org.apache.maven.plugins</groupId>
            <artifactId>maven-surefire-plugin</artifactId>
            <version>3.2.5</version>
        </plugin>
        <plugin>
            <groupId>org.apache.maven.plugins</groupId>
            <artifactId>maven-resources-plugin</artifactId>
            <version>3.3.1</version>
            <executions>
                <execution>
                    <id>copy-resources</id>
                    <phase>validate</phase>
                    <goals>
                        <goal>copy-resources</goal>
                    </goals>
                    <configuration>
                        <outputDirectory>${project.build.outputDirectory}</outputDirectory>
                        <resources>
                            <resource>
                                <directory>${project.basedir}/src/main/resources</directory>
                                <filtering>true</filtering>
                            </resource>
                        </resources>
                    </configuration>
                </execution>
            </executions>
        </plugin>
        <plugin>
            <groupId>org.jacoco</groupId>
            <artifactId>jacoco-maven-plugin</artifactId>
            <version>0.8.11</version>
            <executions>
                <execution>
                    <id>prepare-agent</id>
                    <goals>
                        <goal>prepare-agent</goal>
                    </goals>
                </execution>
                <execution>
                    <id>report</id>
                    <goals>
                        <goal>report</goal>
                    </goals>
                </execution>
            </executions>
        </plugin>
        <plugin>
            <groupId>org.apache.maven.plugins</groupId>
            <artifactId>maven-javadoc-plugin</artifactId>
            <version>${maven-javadoc-plugin.version}</version>
            <configuration>
                <javadocExecutable>${java.home}/bin/javadoc</javadocExecutable>
            </configuration>
            <executions>
                <execution>
                    <id>attach-javadocs</id>
                    <phase>package</phase>
                    <goals>
                        <goal>jar</goal>
                    </goals>
                </execution>
            </executions>
        </plugin>
        <plugin>
            <groupId>org.apache.maven.plugins</groupId>
            <artifactId>maven-gpg-plugin</artifactId>
            <version>3.1.0</version>
            <executions>
                <execution>
                    <id>sign-artifacts</id>
                    <phase>verify</phase>
                    <goals>
                        <goal>sign</goal>
                    </goals>
                    <configuration>
                        <keyname>// not attaching this in the reply</keyname>
                        <gpgArguments>
                            <arg>--pinentry-mode</arg>
                            <arg>loopback</arg>
                        </gpgArguments>
                    </configuration>
                </execution>
            </executions>
        </plugin>
        <plugin>
            <groupId>org.sonatype.plugins</groupId>
            <artifactId>nexus-staging-maven-plugin</artifactId>
            <version>${nexus-staging-maven-plugin.version}</version>
            <extensions>true</extensions>
            <configuration>
                <serverId>ossrh</serverId>
                <nexusUrl>https://s01.oss.sonatype.org/</nexusUrl>
                <autoReleaseAfterClose>true</autoReleaseAfterClose>
            </configuration>
        </plugin>
        <plugin>
            <groupId>org.springframework.boot</groupId>
            <artifactId>spring-boot-maven-plugin</artifactId>
            <configuration>
                <excludes>
                    <exclude>
                        <groupId>org.projectlombok</groupId>
                        <artifactId>lombok</artifactId>
                    </exclude>
                </excludes>
                <skip>true</skip>
            </configuration>
        </plugin>
    </plugins>
</build>

<distributionManagement>
    <snapshotRepository>
        <id>ossrh</id>
        <url>https://s01.oss.sonatype.org/content/repositories/snapshots</url>
    </snapshotRepository>
    <repository>
        <id>ossrh</id>
        <url>https://s01.oss.sonatype.org/service/local/staging/deploy/maven2/</url>
    </repository>
</distributionManagement>

<developers>
    <developer>
        <name>bug hunter98</name>
        <email>saitejathota@gmail.com</email>
        <organization>io.github.bughunter98</organization>
        <organizationUrl>https://github.com/bughunter98</organizationUrl>
    </developer>
</developers>

<scm>
    <connection>scm:git:git://github.com/bughunter98/blogapp-integrations.git</connection>
    <developerConnection>scm:git:ssh://github.com:bughunter98/blogapp-integrations.git</developerConnection>
    <url>https://github.com/bughunter98/blogapp-integrations</url>
</scm>

```

---

<div class="post-metadata">

**Author:** ![ogkuzmin](https://avatars.discourse-cdn.com/v4/letter/o/b9e5f3/32.png) [@ogkuzmin](https://community.sonatype.com/u/ogkuzmin)\
**Post date:** [March 24, 2024, 8:55pm UTC](https://community.sonatype.com/t/maven-deploy-validation-failed-invalid-signature-for-file/12023/7 "2024-03-24T20:55:50Z")

</div>

In my case the problem was that I didn’t upload the gpg public key to server. Check docs [here](https://central.sonatype.org/publish/requirements/gpg/#dealing-with-expired-keys)

The command itself:

```auto
gpg --keyserver keyserver.ubuntu.com --send-keys {INSERT_YOUR_PUBLIC_KEY_HERE}

```

But wait a bit, Sonatype has some cache for keys

---

<div class="post-metadata">

**Author:** ![leo.vu](https://avatars.discourse-cdn.com/v4/letter/l/77aa72/32.png) [@leo.vu](https://community.sonatype.com/u/leo.vu)\
**Post date:** [April 3, 2024, 10:12am UTC](https://community.sonatype.com/t/maven-deploy-validation-failed-invalid-signature-for-file/12023/8 "2024-04-03T10:12:33Z")

</div>

Hi Oleg Kuzmin,

I also have the same problem and wanted to ask

How much time does it take for Sonatype’s server cache to confirm the GPG key?

Thanks

---

<div class="post-metadata">

**Author:** ![tyteishi](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/tyteishi/32/3444_2.png) [@tyteishi](https://community.sonatype.com/u/tyteishi)\
**Post date:** [May 8, 2024, 8:52am UTC](https://community.sonatype.com/t/maven-deploy-validation-failed-invalid-signature-for-file/12023/9 "2024-05-08T08:52:51Z")

</div>

Do you have answer on this question?

---

<div class="post-metadata">

**Author:** ![tyteishi](https://yyz1.discourse-cdn.com/flex047/user_avatar/community.sonatype.com/tyteishi/32/3444_2.png) [@tyteishi](https://community.sonatype.com/u/tyteishi)\
**Post date:** [May 8, 2024, 11:05am UTC](https://community.sonatype.com/t/maven-deploy-validation-failed-invalid-signature-for-file/12023/10 "2024-05-08T11:05:48Z")

</div>

I got successful publishing after 24 hours after uploading my public key to the server. I think, this moment should be reflected in documentation here. [Working with PGP Signatures - The Central Repository Documentation](https://central.sonatype.org/publish/requirements/gpg/#installing-gnupg)

---

<div class="post-metadata">

**Author:** ![iRYO400](https://avatars.discourse-cdn.com/v4/letter/i/f14d63/32.png) [@iRYO400](https://community.sonatype.com/u/iRYO400)\
**Post date:** [May 21, 2024, 2:58pm UTC](https://community.sonatype.com/t/maven-deploy-validation-failed-invalid-signature-for-file/12023/11 "2024-05-21T14:58:15Z")

</div>

Maybe it’s thanks to you a special paragraph has appeared here [Distributing Your Public Key[⚓︎]](https://central.sonatype.org/publish/requirements/gpg/#distributing-your-public-key) and not only that, it also lists supported GPG Keyservers:

> As SKS Keyserver Network is being deprecated we recommend the use an specific GPG keyserver. Current GPG Keyservers supported by Central Servers are:
> 
> - `keyserver.ubuntu.com`
> - `keys.openpgp.org`
> - `pgp.mit.edu`

---

<div class="post-metadata">

**Author:** ![add2ws](https://avatars.discourse-cdn.com/v4/letter/a/58f4c7/32.png) [@add2ws](https://community.sonatype.com/u/add2ws)\
**Post date:** [September 20, 2024, 6:19pm UTC](https://community.sonatype.com/t/maven-deploy-validation-failed-invalid-signature-for-file/12023/12 "2024-09-20T18:19:34Z")

</div>

In my case , just delete the rest GPG keys on my computer, then it’s worked. I hope it is helpul

---

<div class="post-metadata">

**Author:** ![visal](https://avatars.discourse-cdn.com/v4/letter/v/5fc32e/32.png) [@visal](https://community.sonatype.com/u/visal)\
**Post date:** [January 13, 2025, 9:17am UTC](https://community.sonatype.com/t/maven-deploy-validation-failed-invalid-signature-for-file/12023/13 "2025-01-13T09:17:16Z")

</div>

I have that problem too but i use build.gradle to publish  
any solution for me ?  
here is my config :

```auto
   plugins {
     id 'com.android.library'
     id 'maven-publish'
     id 'signing'
     id "com.vanniktech.maven.publish" version "0.28.0"
}
...//other config 
mavenPublishing {
    coordinates("io.bill24", "b24paymentsdk", "1.0.1")
    pom {
        name = "B24 Payment SDK"
        description = "A library provided by B24 Company that enables online payments and digital wallet functionality."
        inceptionYear = "2026"
        url = "https://github.com/Bill24CoLtd/Android-B24PaymentSdk/"
        licenses {
            license {
                name = "The Apache License, Version 2.0"
                url = "http://www.apache.org/licenses/LICENSE-2.0.txt"
                distribution = "repo"
            }
        }
        developers {
            developer {
                id = "Bill24CoLtd"
                name = "Bill24CoLtd"
                url = "https://github.com/Bill24CoLtd/"
            }
        }
        scm {
            url = "https://github.com/Bill24CoLtd/Android-B24PaymentSdk/"
            connection = "scm:git:git://github.com/Bill24CoLtd/Android-B24PaymentSdk.git"
            developerConnection = "scm:git:ssh://git@github.com:Bill24CoLtd/Android-B24PaymentSdk.git"
        }
    }

    publishToMavenCentral("CENTRAL_PORTAL", true)
    signAllPublications()
}

```

 ![Screenshot 2025-01-13 at 16.16.29](https://canada1.discourse-cdn.com/flex047/uploads/communitysonatype/original/2X/c/c97fdafb8a8c7342ee7ad684aafc57a08ca708b9.png)

---

<div class="post-metadata">

**Author:** ![Shadman\_Adman](https://avatars.discourse-cdn.com/v4/letter/s/4af34b/32.png) [@Shadman\_Adman](https://community.sonatype.com/u/Shadman_Adman)\
**Post date:** [February 24, 2025, 7:58pm UTC](https://community.sonatype.com/t/maven-deploy-validation-failed-invalid-signature-for-file/12023/14 "2025-02-24T19:58:38Z")

</div>

Hello. I had the same error.In my case The problem was in the signing section. I fix it by apply the signing manually:

add the plugin in your gradle:

` id("signing")`

then config it:

```auto
signing {
    useInMemoryPgpKeys(
        keystoreProperties["signing.keyId"].toString(),
        File(keystoreProperties["signing.secretKeyFile"].toString()).readText(),
        keystoreProperties["signing.password"].toString()
    )
}

```

hope it helps someone. Happy coding
