Our public keys

These are the public certificates for migrantaction.ca. Use them to encrypt what you send us, or to check that something signed in our name actually came from us. Everything on this page is public certificate material. No secret keys live here, and none ever will.

If you need to reach us safely, start here

Encrypted mail protects what you write. It doesn't hide that you wrote to us, or when, or from where, and for a lot of people that's the part that actually puts them at risk. If that's you, please don't email us at all. Use our secure line instead.

secure.migrantaction.ca runs GlobaLeaks. You can tell us something without giving a name, an email address, or an account. You'll get a 16 digit receipt at the end. Hold onto it, because it's how you come back to read our reply or add anything you left out.

Better still, reach the same service through Tor Browser:

http://6j463ov2a5fg5hqnqg2725lzv46oj46e4tqaztoj76246smeuofzpjid.onion

It's the same place either way. Going through Tor means your network, and anyone watching it, doesn't get to see where you went.

Our organizational anchor

This key signs other keys, and that's the whole of what it does. It carries no email address and no encryption subkey, so there's nothing you can send to it. What it can do is vouch for people. When it signs someone's certificate, that signature ties them back to the Centre. Having no address is also why it will never turn up in an automatic lookup, since those work by email and this key doesn't have one.

Migrant Action Centre

OpenPGP v4 Download .asc, mac-org-v4.asc
Fingerprint
4383A9D6A304C721EED4742B4A08EFC6E8832FBB
Algorithm
EdDSA (ed25519)
Created
2026-06-09
Expires
2031-06-08

Migrant Action Centre

OpenPGP v6 Download .asc, mac-org-v6.asc
Fingerprint
3DFDDC0FDA8ACF1B84C9D4C53784CA135B7FEC099ED50CD16F9A5B82EBABB186
Algorithm
ML-DSA-87 + Ed448
Created
2026-07-22
Expires
2029-07-21

Adi (adi@migrantaction.ca)

Both OpenPGP certificates below are signed by the anchor of the same version. The v4 by 4383A9D6, the v6 by 3DFDDC0F.

Adi

OpenPGP v4 Download .asc, adi-v4.asc
Fingerprint
B16FE02FECC50042523E1CE315986AC8EBD7AFDA
Algorithm
EdDSA (ed25519) signing, ECDH (cv25519) encryption
Created
2026-06-09
Expires
The primary runs to 2031-06-08, but the subkeys expire 2028-06-08, and that's the date that matters in practice
Lookup
Also published to Web Key Directory

Adi

OpenPGP v6 Download .asc, adi-v6.asc
Fingerprint
ED3698D8741DE9C416E27B14E9AB5EAD0AE3223EC97523567C42A782D381C57C
Algorithm
ML-DSA-65 + Ed25519 signing, ML-KEM-768 + X25519 encryption
Created
2026-07-25
Expires
2028-07-25
Lookup
Deliberately not in Web Key Directory. There's more on this below.

Adi Khaitan

S/MIME Download .crt, adi.crt
SHA-256
71:8C:91:E3:30:43:04:B6:78:9E:2C:61:51:D2:C6:25:E9:F7:B3:79:6D:E9:A6:44:05:86:7F:3F:03:6E:03:BB
Serial
503E9A60B1A6A359455A241231AB16A4
Issuer
SSL.com Client Certificate Intermediate CA RSA R2
Validation
Sponsor-validated, policy OID 2.23.140.1.5.3.2. That means the CA checked both the individual and their affiliation with Migrant Action Centre Inc. as a registered entity. Read it off the OID rather than taking our word for it.
Entity
Migrant Action Centre Inc., organizationIdentifier NTRCA-97082
Key
RSA 3072-bit
Valid
2026-03-28 to 2027-03-20
Contents
PEM holding the leaf certificate and SSL.com's intermediate. We leave the root out on purpose. It only means anything if it's already in your trust store, and nobody should be installing a CA root they got off a website.

Which one do I need?

Three formats, because mail software has never managed to agree on one. Find your client below and take what it can actually read.

If you useTake
Apple Mail, Outlook, most workplace or institutional mailThe S/MIME certificate
GnuPG, Enigmail, Thunderbird, Proton, MailvelopeThe v4 OpenPGP certificate
Sequoia (sq), or anything that advertises RFC 9580 supportThe v6 OpenPGP certificate, and we'd prefer it
You're not sureTake the v4 OpenPGP certificate. It works nearly everywhere.

Importing

The easiest route is to let your software fetch the key for you. Web Key Directory hands over the v4 certificate to anyone who looks up the address, and plenty of mail clients do this quietly the first time you write to us. From a terminal:

sq network wkd search adi@migrantaction.ca

That prints the fingerprint it found and labels the certificate UNAUTHENTICATED, which is Sequoia telling you it hasn't verified anything on your behalf. Check what it prints against this page before you go further.

If you'd rather do it by hand, grab a certificate from the links above, look at it, and import it once the fingerprint matches.

sq inspect adi-v6.asc
sq cert import adi-v6.asc

GnuPG will refuse the v6 certificates

Hand a v6 certificate to GnuPG and this is what you get:

gpg: packet(6) with unknown version 6
gpg: read_block: read error: Invalid packet

Your download is fine and nothing is corrupted. GnuPG follows LibrePGP instead of RFC 9580, and it rejects v6 outright rather than falling back to something it understands. This is a disagreement between standards, not a feature still on its way. If GnuPG is what you have, take the v4 certificate and you'll be fine.

gpg --import adi-v4.asc
gpg --fingerprint adi@migrantaction.ca

Automatic lookup

Web Key Directory is the thing that lets mail clients resolve a key from an address without anyone being asked. Ours lives at openpgpkey.migrantaction.ca and runs out of its own repository. It carries v4 OpenPGP only, one certificate per address, because the protocol can't hold two keys for the same person and doesn't carry S/MIME at all.

This page is the source of truth. Web Key Directory publishes a subset of what's listed here, and anything it serves has to match something on this page. If the two ever disagree, believe this page and tell us.

Something looks wrong?

If a fingerprint here doesn't match one you were handed elsewhere, tell us, and hold off on using that key until it's sorted. Same goes if a certificate won't verify, or if you have any reason at all to think a key has been compromised. You won't be wasting anyone's time. A bad key is worth catching early, and we would much rather hear from you twice than not at all.

Reach us whichever way you're most comfortable with:

Seeing [email protected] where an address should be? That's our host hiding addresses from scrapers, and putting them back needs JavaScript. Switch it on for this page if you're comfortable with that. If you'd rather not, KEYS.md carries the same fingerprints and addresses as plain text with nothing to decode, and the secure line above needs neither JavaScript nor our address.