Re: [qubes-users] Confused about verifying signatures
On Fri, August 17, 2018 5:58 am, Patrick Bouldin wrote: >>> On 2018-08-16 15:47, Patrick Bouldin wrote: >>> Hi trying to validate 4.0. I downloaded the qubes-master-signing-key.asc and then not able to progress. I did find Joanna's qubes master signing key footprint, but I don't know how to compare or take the next step... > > Thanks and a quick question. I did get a final "Good signature", but > curious, does that process actually modify the iso at all? Just would > like to know because I pulled the iso file from my other pc and it will > be easier to build the flash there. Assuming you're still talking about the validation process; no, that would not modify the iso. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to qubes-users@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/3921c39f6da73478b34d77ff5c96bb3a.squirrel%40tt3j2x4k5ycaa5zt.onion. For more options, visit https://groups.google.com/d/optout.
Re: [qubes-users] Confused about verifying signatures
On Thursday, August 16, 2018 at 6:43:50 PM UTC-4, Andrew David Wong wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA512 > > On 2018-08-16 17:35, Andrew David Wong wrote: > > On 2018-08-16 15:47, Patrick Bouldin wrote: > >> Hi trying to validate 4.0. I downloaded the > >> qubes-master-signing-key.asc and then not able to progress. I did > >> find Joanna's qubes master signing key footprint, but I don't know > >> how to compare or take the next step... > > > >> I did this with 3.0 a few years ago but can't remember... > > > >> I did check the web site and still don't know. > > > >> Thanks. > > > > > > If you just want to see the fingerprint of the key you downloaded as a > > file so that you can compare it to the fingerprint you obtained > > through another channel, this is probably the simplest way: > > > > $ gpg2 qubes-master-signing-key.asc > > gpg: WARNING: no command supplied. Trying to guess what you mean ... > > pub rsa4096 2010-04-01 [SC] > > 427F11FD0FAA4B080123F01CDDFA1A3E36879494 > > uid Qubes Master Signing Key > > > > If you're using gpg instead of gpg2, there's the --with-fingerprint > option: > > $ gpg --with-fingerprint qubes-master-signing-key.asc > gpg: keyring `/home/user/.gnupg/secring.gpg' created > pub 4096R/36879494 2010-04-01 Qubes Master Signing Key > Key fingerprint = 427F 11FD 0FAA 4B08 0123 F01C DDFA 1A3E 3687 9494 > > - -- > Andrew David Wong (Axon) > Community Manager, Qubes OS > https://www.qubes-os.org > > -BEGIN PGP SIGNATURE- > > iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAlt1/gQACgkQ203TvDlQ > MDASEA//a1TzjaaAPwNS12GHWollY2WGqpSK7RZNEsHkBSJYPTaNayqOHXx2yzQ2 > Re5uPgpHofCYxNx96VhKFDE9rIo17ozrLrr+ZywESDn5GoIzM7BtUaKTR5GQWZx1 > E9vALH50GtNJAdb/SumOcdsDxrDj139wjcAuypWBDXK6lxF2hR/nDr7RZMxvfwTF > uixM4LP7zhwOafLAbhXsa9wyu6ZsooTicdiSit+iQPk15oxLGjUSncQcIYuRLdvX > yLht5/2ZPST1Jm9HyEEwOllMN4eFrMAc/StHhVxPWlUiqtr3xMki3IWZV+xi8sMh > Ri0HmASNzLn4JwNQnPFQqnT+Z4Im8tiH24w/T8eHhP2hLo8tEfd5aq26xl0NoRbU > Hcc69XXjzITQIi2d7YZHgtNgrml8zCjTRF+9p14cLyFFl2ISJsEZeus/egQWE6Rv > aRMR+IPDG8HqCWepV+Y/of3lb+uqd7SBVJdcRavf/Jrlf/9AOeCRDUteTGsiJE14 > U9FksIiiZRclcHR+NFeZSbINvwlwNx2tO7o7YcbBxmqPMzsg20gHYfuI3GAnMY/R > yHX52v6sXcM/4Y08TrTTHV1l+/EPUOnOb3adaIejNyEiHB5WiQ3fgoEwpX3GkKTb > iCt4TJJKo6KRSG2EzMMLH0s69gGphqLtgC5+zEQg4X7NWpFzWX4= > =cBsO > -END PGP SIGNATURE- Thanks and a quick question. I did get a final "Good signature", but curious, does that process actually modify the iso at all? Just would like to know because I pulled the iso file from my other pc and it will be easier to build the flash there. -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to qubes-users@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/8b5b5988-ee3d-43ab-a229-e1a2d176e27f%40googlegroups.com. For more options, visit https://groups.google.com/d/optout.
Re: [qubes-users] Confused about verifying signatures
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 On 2018-08-16 17:35, Andrew David Wong wrote: > On 2018-08-16 15:47, Patrick Bouldin wrote: >> Hi trying to validate 4.0. I downloaded the >> qubes-master-signing-key.asc and then not able to progress. I did >> find Joanna's qubes master signing key footprint, but I don't know >> how to compare or take the next step... > >> I did this with 3.0 a few years ago but can't remember... > >> I did check the web site and still don't know. > >> Thanks. > > > If you just want to see the fingerprint of the key you downloaded as a > file so that you can compare it to the fingerprint you obtained > through another channel, this is probably the simplest way: > > $ gpg2 qubes-master-signing-key.asc > gpg: WARNING: no command supplied. Trying to guess what you mean ... > pub rsa4096 2010-04-01 [SC] > 427F11FD0FAA4B080123F01CDDFA1A3E36879494 > uid Qubes Master Signing Key > If you're using gpg instead of gpg2, there's the --with-fingerprint option: $ gpg --with-fingerprint qubes-master-signing-key.asc gpg: keyring `/home/user/.gnupg/secring.gpg' created pub 4096R/36879494 2010-04-01 Qubes Master Signing Key Key fingerprint = 427F 11FD 0FAA 4B08 0123 F01C DDFA 1A3E 3687 9494 - -- Andrew David Wong (Axon) Community Manager, Qubes OS https://www.qubes-os.org -BEGIN PGP SIGNATURE- iQIzBAEBCgAdFiEEZQ7rCYX0j3henGH1203TvDlQMDAFAlt1/gQACgkQ203TvDlQ MDASEA//a1TzjaaAPwNS12GHWollY2WGqpSK7RZNEsHkBSJYPTaNayqOHXx2yzQ2 Re5uPgpHofCYxNx96VhKFDE9rIo17ozrLrr+ZywESDn5GoIzM7BtUaKTR5GQWZx1 E9vALH50GtNJAdb/SumOcdsDxrDj139wjcAuypWBDXK6lxF2hR/nDr7RZMxvfwTF uixM4LP7zhwOafLAbhXsa9wyu6ZsooTicdiSit+iQPk15oxLGjUSncQcIYuRLdvX yLht5/2ZPST1Jm9HyEEwOllMN4eFrMAc/StHhVxPWlUiqtr3xMki3IWZV+xi8sMh Ri0HmASNzLn4JwNQnPFQqnT+Z4Im8tiH24w/T8eHhP2hLo8tEfd5aq26xl0NoRbU Hcc69XXjzITQIi2d7YZHgtNgrml8zCjTRF+9p14cLyFFl2ISJsEZeus/egQWE6Rv aRMR+IPDG8HqCWepV+Y/of3lb+uqd7SBVJdcRavf/Jrlf/9AOeCRDUteTGsiJE14 U9FksIiiZRclcHR+NFeZSbINvwlwNx2tO7o7YcbBxmqPMzsg20gHYfuI3GAnMY/R yHX52v6sXcM/4Y08TrTTHV1l+/EPUOnOb3adaIejNyEiHB5WiQ3fgoEwpX3GkKTb iCt4TJJKo6KRSG2EzMMLH0s69gGphqLtgC5+zEQg4X7NWpFzWX4= =cBsO -END PGP SIGNATURE- -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to qubes-users@googlegroups.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/9ce6f7d7-47ca-8c8b-bc3b-01668d67eb56%40qubes-os.org. For more options, visit https://groups.google.com/d/optout.