These were the steps used to set up a new package signing key
that had Cumulus references in it.

# Go interactive, but have the results spit out to pubring.kbx
# When asked, choose default encoding, 4096 bits, etc
# The end result looks something like:
# Cumulus Dev Package (Cumulus signing key for dev release track packages) <cdevpackage@cumulusnetworks.com>
gpg --no-default-keyring --keyring ./pubring.kbx --full-generate-key

# Show the keys
gpg --no-default-keyring --keyring ./pubring.kbx --list-keys
gpg --no-default-keyring --keyring ./pubring.kbx --list-secret-keys

# Optional - Export the keys
# The signing code doesn't use exported keys, but for sanity checking...
gpg --no-default-keyring --keyring ./pubring.kbx --armor --output dev-pub.asc --export cdevpackage
gpg --no-default-keyring --keyring ./pubring.kbx --armor --output dev-secret.asc --export-secret-key cdevpackage


# Optional - To delete keys
#  If they happen to get created under your ~/.gnupg because you missed using
# --no-default-keyring...
# NOTE that this popped up X notification window, so may not work over an ssh connection.
 gpg --delete-secret-keys <name in email>.


# Populate gnupg/openpgp-revocs.d/
# Get the revocation key ( look for the last one created )
cp ~/.gnupg/openpgp-revocs.d/313D749446C61F34DBAD931C5759A5174F85C3FC.rev ./gnupg/openpgp-revocs.d/

#
# Populate ~/.gnupg/private-keys-v1.d/
There were 2 generated here, despite using --no-default-keyring.
I copied  them based on timestamp.

 
# copy over the following to debian-signing/gnupg
 openpgp-revocs.d/
 private-keys-v1.d/
 pubring.kbx

# You should be good at this point.

