Re: [qubes-users] Confused about verifying signatures

2018-08-17 Thread 'awokd' via qubes-users
On Fri, August 17, 2018 5:58 am, Patrick Bouldin wrote:

>>> On 2018-08-16 15:47, Patrick Bouldin wrote:
>>>
 Hi trying to validate 4.0. I downloaded the
 qubes-master-signing-key.asc and then not able to progress. I did
 find Joanna's qubes master signing key footprint, but I don't know
 how to compare or take the next step...

>
> Thanks and a quick question. I did get a final "Good signature", but
> curious, does that process actually modify the iso at all? Just would
> like to know because I pulled the iso file from my other pc and it will
> be easier to build the flash there.

Assuming you're still talking about the validation process; no, that would
not modify the iso.


-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/3921c39f6da73478b34d77ff5c96bb3a.squirrel%40tt3j2x4k5ycaa5zt.onion.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Confused about verifying signatures

2018-08-16 Thread Patrick Bouldin
On Thursday, August 16, 2018 at 6:43:50 PM UTC-4, Andrew David Wong wrote:
> -BEGIN PGP SIGNED MESSAGE-
> Hash: SHA512
> 
> On 2018-08-16 17:35, Andrew David Wong wrote:
> > On 2018-08-16 15:47, Patrick Bouldin wrote:
> >> Hi trying to validate 4.0. I downloaded the 
> >> qubes-master-signing-key.asc and then not able to progress. I did 
> >> find Joanna's qubes master signing key footprint, but I don't know 
> >> how to compare or take the next step...
> > 
> >> I did this with 3.0 a few years ago but can't remember...
> > 
> >> I did check the web site and still don't know.
> > 
> >> Thanks.
> > 
> > 
> > If you just want to see the fingerprint of the key you downloaded as a
> > file so that you can compare it to the fingerprint you obtained
> > through another channel, this is probably the simplest way:
> > 
> >   $ gpg2 qubes-master-signing-key.asc
> >   gpg: WARNING: no command supplied.  Trying to guess what you mean ...
> >   pub   rsa4096 2010-04-01 [SC]
> > 427F11FD0FAA4B080123F01CDDFA1A3E36879494
> >   uid   Qubes Master Signing Key
> > 
> 
> If you're using gpg instead of gpg2, there's the --with-fingerprint
> option:
> 
>   $ gpg --with-fingerprint qubes-master-signing-key.asc 
>   gpg: keyring `/home/user/.gnupg/secring.gpg' created
>   pub  4096R/36879494 2010-04-01 Qubes Master Signing Key
>   Key fingerprint = 427F 11FD 0FAA 4B08 0123  F01C DDFA 1A3E 3687 9494
> 
> - -- 
> Andrew David Wong (Axon)
> Community Manager, Qubes OS
> https://www.qubes-os.org
> 
> -BEGIN PGP SIGNATURE-
> 
> iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAlt1/gQACgkQ203TvDlQ
> MDASEA//a1TzjaaAPwNS12GHWollY2WGqpSK7RZNEsHkBSJYPTaNayqOHXx2yzQ2
> Re5uPgpHofCYxNx96VhKFDE9rIo17ozrLrr+ZywESDn5GoIzM7BtUaKTR5GQWZx1
> E9vALH50GtNJAdb/SumOcdsDxrDj139wjcAuypWBDXK6lxF2hR/nDr7RZMxvfwTF
> uixM4LP7zhwOafLAbhXsa9wyu6ZsooTicdiSit+iQPk15oxLGjUSncQcIYuRLdvX
> yLht5/2ZPST1Jm9HyEEwOllMN4eFrMAc/StHhVxPWlUiqtr3xMki3IWZV+xi8sMh
> Ri0HmASNzLn4JwNQnPFQqnT+Z4Im8tiH24w/T8eHhP2hLo8tEfd5aq26xl0NoRbU
> Hcc69XXjzITQIi2d7YZHgtNgrml8zCjTRF+9p14cLyFFl2ISJsEZeus/egQWE6Rv
> aRMR+IPDG8HqCWepV+Y/of3lb+uqd7SBVJdcRavf/Jrlf/9AOeCRDUteTGsiJE14
> U9FksIiiZRclcHR+NFeZSbINvwlwNx2tO7o7YcbBxmqPMzsg20gHYfuI3GAnMY/R
> yHX52v6sXcM/4Y08TrTTHV1l+/EPUOnOb3adaIejNyEiHB5WiQ3fgoEwpX3GkKTb
> iCt4TJJKo6KRSG2EzMMLH0s69gGphqLtgC5+zEQg4X7NWpFzWX4=
> =cBsO
> -END PGP SIGNATURE-

Thanks and a quick question. I did get a final "Good signature", but curious, 
does that process actually modify the iso at all? Just would like to know 
because I pulled the iso file from my other pc and it will be easier to build 
the flash there.

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/8b5b5988-ee3d-43ab-a229-e1a2d176e27f%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.


Re: [qubes-users] Confused about verifying signatures

2018-08-16 Thread Andrew David Wong
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA512

On 2018-08-16 17:35, Andrew David Wong wrote:
> On 2018-08-16 15:47, Patrick Bouldin wrote:
>> Hi trying to validate 4.0. I downloaded the 
>> qubes-master-signing-key.asc and then not able to progress. I did 
>> find Joanna's qubes master signing key footprint, but I don't know 
>> how to compare or take the next step...
> 
>> I did this with 3.0 a few years ago but can't remember...
> 
>> I did check the web site and still don't know.
> 
>> Thanks.
> 
> 
> If you just want to see the fingerprint of the key you downloaded as a
> file so that you can compare it to the fingerprint you obtained
> through another channel, this is probably the simplest way:
> 
>   $ gpg2 qubes-master-signing-key.asc
>   gpg: WARNING: no command supplied.  Trying to guess what you mean ...
>   pub   rsa4096 2010-04-01 [SC]
> 427F11FD0FAA4B080123F01CDDFA1A3E36879494
>   uid   Qubes Master Signing Key
> 

If you're using gpg instead of gpg2, there's the --with-fingerprint
option:

  $ gpg --with-fingerprint qubes-master-signing-key.asc 
  gpg: keyring `/home/user/.gnupg/secring.gpg' created
  pub  4096R/36879494 2010-04-01 Qubes Master Signing Key
  Key fingerprint = 427F 11FD 0FAA 4B08 0123  F01C DDFA 1A3E 3687 9494

- -- 
Andrew David Wong (Axon)
Community Manager, Qubes OS
https://www.qubes-os.org

-BEGIN PGP SIGNATURE-

iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAlt1/gQACgkQ203TvDlQ
MDASEA//a1TzjaaAPwNS12GHWollY2WGqpSK7RZNEsHkBSJYPTaNayqOHXx2yzQ2
Re5uPgpHofCYxNx96VhKFDE9rIo17ozrLrr+ZywESDn5GoIzM7BtUaKTR5GQWZx1
E9vALH50GtNJAdb/SumOcdsDxrDj139wjcAuypWBDXK6lxF2hR/nDr7RZMxvfwTF
uixM4LP7zhwOafLAbhXsa9wyu6ZsooTicdiSit+iQPk15oxLGjUSncQcIYuRLdvX
yLht5/2ZPST1Jm9HyEEwOllMN4eFrMAc/StHhVxPWlUiqtr3xMki3IWZV+xi8sMh
Ri0HmASNzLn4JwNQnPFQqnT+Z4Im8tiH24w/T8eHhP2hLo8tEfd5aq26xl0NoRbU
Hcc69XXjzITQIi2d7YZHgtNgrml8zCjTRF+9p14cLyFFl2ISJsEZeus/egQWE6Rv
aRMR+IPDG8HqCWepV+Y/of3lb+uqd7SBVJdcRavf/Jrlf/9AOeCRDUteTGsiJE14
U9FksIiiZRclcHR+NFeZSbINvwlwNx2tO7o7YcbBxmqPMzsg20gHYfuI3GAnMY/R
yHX52v6sXcM/4Y08TrTTHV1l+/EPUOnOb3adaIejNyEiHB5WiQ3fgoEwpX3GkKTb
iCt4TJJKo6KRSG2EzMMLH0s69gGphqLtgC5+zEQg4X7NWpFzWX4=
=cBsO
-END PGP SIGNATURE-

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/9ce6f7d7-47ca-8c8b-bc3b-01668d67eb56%40qubes-os.org.
For more options, visit https://groups.google.com/d/optout.