Our public keys
These are the public certificates for migrantaction.ca. Use them to encrypt what
you send us, or to check that something signed in our name actually came from us. Everything
on this page is public certificate material. No secret keys live here, and none ever will.
If you need to reach us safely, start here
Encrypted mail protects what you write. It doesn't hide that you wrote to us, or when, or from where, and for a lot of people that's the part that actually puts them at risk. If that's you, please don't email us at all. Use our secure line instead.
secure.migrantaction.ca runs GlobaLeaks. You can tell us something without giving a name, an email address, or an account. You'll get a 16 digit receipt at the end. Hold onto it, because it's how you come back to read our reply or add anything you left out.
Better still, reach the same service through Tor Browser:
http://6j463ov2a5fg5hqnqg2725lzv46oj46e4tqaztoj76246smeuofzpjid.onion
It's the same place either way. Going through Tor means your network, and anyone watching it, doesn't get to see where you went.
Our organizational anchor
This key signs other keys, and that's the whole of what it does. It carries no email address and no encryption subkey, so there's nothing you can send to it. What it can do is vouch for people. When it signs someone's certificate, that signature ties them back to the Centre. Having no address is also why it will never turn up in an automatic lookup, since those work by email and this key doesn't have one.
- Fingerprint
- 4383A9D6A304C721EED4742B4A08EFC6E8832FBB
- Algorithm
- EdDSA (ed25519)
- Created
- 2026-06-09
- Expires
- 2031-06-08
- Fingerprint
- 3DFDDC0FDA8ACF1B84C9D4C53784CA135B7FEC099ED50CD16F9A5B82EBABB186
- Algorithm
- ML-DSA-87 + Ed448
- Created
- 2026-07-22
- Expires
- 2029-07-21
Adi (adi@migrantaction.ca)
Both OpenPGP certificates below are signed by the anchor of the same version. The v4 by
4383A9D6, the v6 by 3DFDDC0F.
- Fingerprint
- B16FE02FECC50042523E1CE315986AC8EBD7AFDA
- Algorithm
- EdDSA (ed25519) signing, ECDH (cv25519) encryption
- Created
- 2026-06-09
- Expires
- The primary runs to 2031-06-08, but the subkeys expire 2028-06-08, and that's the date that matters in practice
- Lookup
- Also published to Web Key Directory
- Fingerprint
- ED3698D8741DE9C416E27B14E9AB5EAD0AE3223EC97523567C42A782D381C57C
- Algorithm
- ML-DSA-65 + Ed25519 signing, ML-KEM-768 + X25519 encryption
- Created
- 2026-07-25
- Expires
- 2028-07-25
- Lookup
- Deliberately not in Web Key Directory. There's more on this below.
- SHA-256
- 71:8C:91:E3:30:43:04:B6:78:9E:2C:61:51:D2:C6:25:E9:F7:B3:79:6D:E9:A6:44:05:86:7F:3F:03:6E:03:BB
- Serial
- 503E9A60B1A6A359455A241231AB16A4
- Issuer
- SSL.com Client Certificate Intermediate CA RSA R2
- Validation
- Sponsor-validated, policy OID
2.23.140.1.5.3.2. That means the CA checked both the individual and their affiliation with Migrant Action Centre Inc. as a registered entity. Read it off the OID rather than taking our word for it. - Entity
- Migrant Action Centre Inc., organizationIdentifier
NTRCA-97082 - Key
- RSA 3072-bit
- Valid
- 2026-03-28 to 2027-03-20
- Contents
- PEM holding the leaf certificate and SSL.com's intermediate. We leave the root out on purpose. It only means anything if it's already in your trust store, and nobody should be installing a CA root they got off a website.
Which one do I need?
Three formats, because mail software has never managed to agree on one. Find your client below and take what it can actually read.
| If you use | Take |
|---|---|
| Apple Mail, Outlook, most workplace or institutional mail | The S/MIME certificate |
| GnuPG, Enigmail, Thunderbird, Proton, Mailvelope | The v4 OpenPGP certificate |
Sequoia (sq), or anything that advertises RFC 9580 support | The v6 OpenPGP certificate, and we'd prefer it |
| You're not sure | Take the v4 OpenPGP certificate. It works nearly everywhere. |
Importing
The easiest route is to let your software fetch the key for you. Web Key Directory hands over the v4 certificate to anyone who looks up the address, and plenty of mail clients do this quietly the first time you write to us. From a terminal:
sq network wkd search adi@migrantaction.ca
That prints the fingerprint it found and labels the certificate UNAUTHENTICATED,
which is Sequoia telling you it hasn't verified anything on your behalf. Check what it prints
against this page before you go further.
If you'd rather do it by hand, grab a certificate from the links above, look at it, and import it once the fingerprint matches.
sq inspect adi-v6.asc
sq cert import adi-v6.asc
GnuPG will refuse the v6 certificates
Hand a v6 certificate to GnuPG and this is what you get:
gpg: packet(6) with unknown version 6
gpg: read_block: read error: Invalid packet
Your download is fine and nothing is corrupted. GnuPG follows LibrePGP instead of RFC 9580, and it rejects v6 outright rather than falling back to something it understands. This is a disagreement between standards, not a feature still on its way. If GnuPG is what you have, take the v4 certificate and you'll be fine.
gpg --import adi-v4.asc
gpg --fingerprint adi@migrantaction.ca
Automatic lookup
Web Key Directory is the thing that lets mail clients resolve a key from an address without
anyone being asked. Ours lives at openpgpkey.migrantaction.ca and runs out of its
own repository. It carries v4 OpenPGP only, one certificate per address, because the protocol
can't hold two keys for the same person and doesn't carry S/MIME at all.
This page is the source of truth. Web Key Directory publishes a subset of what's listed here, and anything it serves has to match something on this page. If the two ever disagree, believe this page and tell us.
Something looks wrong?
If a fingerprint here doesn't match one you were handed elsewhere, tell us, and hold off on using that key until it's sorted. Same goes if a certificate won't verify, or if you have any reason at all to think a key has been compromised. You won't be wasting anyone's time. A bad key is worth catching early, and we would much rather hear from you twice than not at all.
Reach us whichever way you're most comfortable with:
- secure.migrantaction.ca, if you'd rather not put a name to it. This is also the one to use if what worries you is this page itself, since it doesn't depend on anything here being honest.
- Email adi@migrantaction.ca.
- Raise it on the repository, where it'll be public and other people can see the fix.
- The contact form on our main site. It's the least private option here, because it runs through Action Network and your message passes through them on the way to us.
Seeing [email protected] where an address should be? That's our host hiding
addresses from scrapers, and putting them back needs JavaScript. Switch it on for this page if
you're comfortable with that. If you'd rather not, KEYS.md carries the
same fingerprints and addresses as plain text with nothing to decode, and the secure line above
needs neither JavaScript nor our address.