- one in the Maven installation (
$M2_HOME/conf/pubring.pgp, configured in the installation settings file)
- one in the user's Maven directory (
$HOME/.m2/pubring.pgp, configured in the installation settings file)
- others added to
The Maven installation will contain the keys of several well known individuals and repositories. Should a user not wish to accept this initial set of keys, they can simply remove the installation key ring and manually install keys they wish to trust. As described later, a trust store and automatic retrieval from a key server is not used, but is a future consideration.