Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

List Of Linux Distro Public OpenPGP Keys


  • Please log in to reply
2 replies to this topic

#1 Guest_hollowface_*

Guest_hollowface_*

  • Guests
  • OFFLINE
  •  

Posted 12 June 2016 - 07:27 PM

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

I hear about GPG more and more, especially in regards to verifying Linux ISOs. While I've read a lot about it I'm not a user, but I decided to bite the bullet, do some experimenting with GPG. I've made a key pair for myself, even signed the Linux Mint key :P. You can download a copy of my personal notes on using GPG from here ( https://mega.nz/#!9opQSbSQ!dhh7sTh7HaGvUv_PbBd8ymuJ8S4hC_wvFTOdAqMPy9k ) if you're interested; I cannot promise they're perfect. Alternatively check out the official documentation here ( https://www.gnupg.org/gph/en/manual/c14.html ) and here ( https://www.gnupg.org/documentation/manuals/gnupg/ ) to learn more about GPG/OpenPGP. Or, just google around.

One thing I notice a lot is a Linux distro will provide a detached signatured and then doesn't actually provide you with their public key, tell you which keyserver they've submitted it to (if any), or even give you the key ID so you can search for it. To be clear, you can use the verify option to determine which key is needed but this is only helpful if you can trust the the file you've downloaded hasn't been tampered with (which is why you wanted the key in the first place!). Some distros do provide all the information you need, but not all of them make it easy to find.

Personally I verify my ISOs with a checksum, but for those who are using OpenPGP signatures this has to be annoying? I was thinking this thread could serve as a place to post this kind of information, so it's easy to find (eg: this is the key you need for this distro release, and this is where you can get it). 

Since this posting is about OpenPGP keys, it seemed fitting to sign this post. If you want to verify this post is from
me (and hasn't been altered since I posted it) you can get my public key from here ( https://mega.nz/#!Q9BRlLJY!SZdrNsR4Vr0NnH5HFNLCFGQ1ki_Bh7ITTtRh-Kd8EoY  ).

Happy verifying. :)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCgAGBQJXXfv5AAoJEA8RseiN1bnCungQAKg9PxDqMGoG22nDRUszscbF
PnUXXnyqxrfk/vFOPn5pFFs5ydtRS6Cq+29leGZu3XQcB03zZMDPfbOs1XHv9PlP
uZ75cnZvYoiMQ/Ab4qHpPBS004EZbXWH2/oYvAAKrttUNPVBs+nqLX2XscaDzemd
kdVC5eMk7WlIPybd3mnr7T0hzPCR08yMELff0rzYvpL2kg9r2gTg8N4YP7+J8IAG
zZKrHUdN4wOwy3tWjRwn3gmf5GdOKTzfX7QZUoT9fYaXWbvE/MwLpeV3f/UnTu2P
Kp3boGRtk97nnT4K9IBcXtzgAmenmZgGd4GACCihuBbevTG5D+PamX/RyPyA+x1c
xT2Qgp1TNk//1ukBvBof6ND9VTI4ybJQmuJXZ0QQ8/ht000ergCwI8OkyxBpcSOg
6DoG1k9dQj1IBnDjJOx3ZQy+xJOjvsFT9EaKTD+ktqV2/iqyLzGXGkSkKJJeTVzg
WCN39Y592GufQDhqwna4lP7/wVig0GxGYGlASsoXCwS330i5IW7/Gn3sXqz6oG9s
4ODtUu2jQVHXTR6sRqJ3EyIU6WEUwXtv5l4SEEFxKHQiNIxaLpZV1H95kvgbKM0t
zAsMTdyiXgwcmT1qfro9jni3bATIutbzvx416geJyjS7RYX86w13EcjrdUD1et/A
zQ2DfqkAKA7zP3xOpwiv
=cuJP
-----END PGP SIGNATURE-----


Edited by hollowface, 12 June 2016 - 07:58 PM.


BC AdBot (Login to Remove)

 


#2 Guest_hollowface_*

Guest_hollowface_*

  • Guests
  • OFFLINE
  •  

Posted 12 June 2016 - 07:29 PM

Linux Mint 18 Cinnamon 64bit Beta:
Signature is for a checksum file, which is for the ISO.

Signature:
- http://mirror.csclub.uwaterloo.ca/linuxmint/testing/sha256sum.txt.gpg
File:
- http://mirror.csclub.uwaterloo.ca/linuxmint/testing/sha256sum.txt
Public Key IDs:
- A25BAE09
Keyservers:
- "keyserver.ubuntu.com" (Unknown if submitted by Linux Mint)
Public Keys:
- A25BAE09:
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v2

mQINBFdW7VcBEAD0e2lAJwbmLKZI3t1uZkQBM0FbJiQVPf98W9mnHDEuOfFOmbp0
1RYmi/b7BkH10UFDS1vcezbXKB5S6OjcZId/X5ncv9ddDdzeKluUEI4f2fL6xvWz
FrD9QjEKgYhph4hzo5BaDWk1GuujhYgx5EElcMHlIPT9YnhaaC+EkxOWxnaTVDgX
Md8KonN9hSS6G8Z/5ZftJANOAmQWRhGRhBszetSa0BabIxK5AAaJMElmKby1avZ3
m2cdX/DkV4XmI7WLExuaXk/geq6u//vzP5FDZcnDsaa4mj74wujkI78hLrucB+ld
IAkIe4lkCrXhO7M0/I9KPEk6t6e2AkhV2XWiwzMu5ZpMM4J4BB8o54nJP9WzJAvp
LvzOIZjq+7h7dQuYy9quVmy42mxix3nQGuA7BC1PYCntFmG0eTx8++NYNC+Iv5pK
Vj05u1RvbjrFZIAEM7XEo1fQ5Oa7xVanmFmrPScLgJQx05d6o4wpLzyLmjjY94Iw
M4r9EoAuAPjo3wk0RHdL98NtKpMMISlC2fGhaxMJI6eSef0tmKviMi6TRfwlqMMQ
lF5/y102UcoDI3wfviUGt8E7mk6uiYJ95JroIeCgW2HNfdZaksxJP/QFf7kBkXHT
D1SLHc9uUK/7Hd5RVgOGLOalIboOqOnXjTuavlsuQ1kVxK9r/wTFAY5eqQARAQAB
tC9MaW51eCBNaW50IElTTyBTaWduaW5nIEtleSA8cm9vdEBsaW51eG1pbnQuY29t
PokCHAQQAQoABgUCV1rJDgAKCRB4e0PdIS1Bs5leD/4svHfp+lmkg2oqi/G7fRXm
ZKs1AYHidBm6KV7QaEeJiWscYIfo5wLKdMQCuWSp73YgcYwTVnqnmn9D6FjdqYqQ
ojGwLKOTBTr64biMzdU32SfNyZGe8aPvbBy37wsE/QnLFh0X0M4ag7ZRiE5bB9eK
ckJFcqYi5Di6EpAT3PkDfLDyakRRBHIZgJ2luix6x2pnYjuLB4ekXP7xVX3Qvz1x
TC5wYtvtm4ZqTHK7N4UOT2r9qsb9q/XbogHiOREUbHlsVlrRuP3VyVQ9nccWmtDv
1KEOB+krurJilv71ZG9KjY4/zRot3AxYNALE4+To77d8ojlxzDAQ7N90eyPKPqSC
yCpZBBximCnNXP1AC2xoyHVg8Tw7q4ZuhfgJ8YRl4IIFUe8IaRkOTTalEb+wARei
AbBqfPp018nSBokiAqERO8AVFv5mQDTX6ashNsuZ+J1zZWJU/L0vNhynnltClhHm
ankW0jmaslDJBqWQE6Sbrv90Gy930GZP7DCi5uut8t6kf4g7uWyY8kwwBGKav4oK
EO4GH7uZQ8giZyR4K46M1bJWviO90opL2bGo9mFPtS+4gYvZ67y2n42EUAby04Uf
r9EmpGf9tMiHRiyBJSlKPWjKwuMIkqHK8l7uG3tSWY5f+HTNhKUOEnS43HtITqa9
ALNGuNu/eUCi5bxax0A9kokCNwQTAQoAIQUCV1btVwIbAwULCQgHAwUVCgkICwUW
AgMBAAIeAQIXgAAKCRAwD4RroluuCeOvEADxnaGSNbWXXsCv9caW7jil1fA0DJpo
zAtLHlYP1mLNODTkaLPRmzTIiTqkksDNijoxAUNMfvMk0ctLdFL32Zq5XVTnW72B
eXoAlapMGRBq0E1WrtrtglbHTb6ZtPfFwoAjXEAjkx5GgEYUbTJREuWR0ZaXRy+X
9/0/UJu6IQjgow9HdhEuQj6nkOEvUvLYnDmS+MbTofMZ7qAgqaNeozSLz55/fK3U
2cYYT6/Wuz0nLsz+QgjCKB8mZE+uHP6/5CcdPbiez3h9fa2HjGuvHx21kXhH+YB0
ty1CNGUysB9ovRj1ryVqlqv3V0qvGE1sJOCQsxLlrF081bUKUdMi1KJkVBxbXiLq
wG8lacrMkmu9A83RdTtiD8UyLu631ydx0Mf2WmQpjhpZ/v/6BWmn/KhTav2RyzTs
Igzz5DJtCi/lcFrb9NsukEXHGiXDR1H6ekZhhuNDyPdzlFxuWhvGtOj6ABqzL4IS
CmgN6XBBViF+gK+iGYKfpYa3vGh7ybVEb+ZtzT614ncQtp10toogFhQ8DofNyUDp
G0pQ/rFZ3C1Qd+1qlMLV0GVcfSYFo+1+p8Qe52LLqiD6JkVQdi55NVN+O4X4UDE7
elgBkM+qqkWSMxuw+H0v2kB6hNSoJMbShhIRERvEtzwItdtx2WzdpPYdchnyDCrM
C6FY++PXXQj10okCHAQQAQgABgUCV1tpvQAKCRBjIP6vXNX9v+4MEADSq5sFjtop
DXdPQwrGXH/qPwG08tsWHbVGfNWSm7Qh8GbfLATKltJYqG2qMx9XB2GGU+gXW0z8
BueR+WGqALwoC3HFEjIbefjPbhv/gVnCL5gFZvCvfcRm7s9I+7VFYMTFGYWqre4h
KexC72ufwZ/BltRYVgJ9n3yMsVBeHQaPg6S8KbTm9QaCZ5jrpJkityQPo+zGBJUk
Oki/Go+g7QW1JUMBaUVRU0aQlNXHYcLZf7S2btxJbRvvYWOyjAlqrtTvmztpk8BH
O0TsnuMRtCFNq6SufP5Hh6Rk2SSUjhTVKXU4eYuvDiJ5/gm/+YuUyro6hPM/KMIt
SdRtVkz4Y99iLojbeeE1b1CPLc4vPAATBzdVLJhPI5oVWt+nKBgFFJ4zwvAkvfe7
zAHZGe4uE7NgioKLCZWBDkJDxW1B+ukGC5/ib5jtByRYUvvllfgPXOdvTSRg3axs
d4TUzi4YGq0YNKlYLqDLK5ZbWohSPys0JoOSInvXtL3IrIss8XFD3a6RTx9ltWCS
4kVN53yhxpqTkkgRLHL2Cj2Rmf1aDrpXaLUpKP718439YafSmiRnMrtiTU0WvRfr
A0AoEQDx8xxdDk8iT4f61wRibl+mvB1dxePrvzUmxd+s1oCbxkqQgiZ1CzT/BASN
NmHLIpjTBAJgN4IlmG2WCsrLtoJAcd0q6IkCHAQQAQgABgUCV13quQAKCRAPEbHo
jdW5wipWD/0eW08btLAxqFYbvLU7UaNaaDdf928IX3C4VDbqhcfkeDhGr9DamT0T
iRfw2CaIB5MDUaobJ4GdB8MIC0cEM3ZzvFcyIYkjphnldEqNm8wpdJ3J4wbYSdKN
+nqxFAn03C/ZlGIvSebQJb+pq8r8/AADGsDJ2dsqLAYOVtHrt12hER1+l39qhlFr
8VE9hp/oLQGeDMIvYXkhC0/NI+3yZHW4DdMk6bo64EtmAUhpPMViUhOLvDVaJyCq
RTiydbTYLlcmT5RdnsnpbMvgattZD2Tlt2hRy4l0x1KvVCTelOqY9v811ODyn+tb
GcriZ6sjIOm3SOOR0SLgUJlKI/TLA8OwMWJZPjWMI0VjD6tw6i6MBpTeHIg50T8S
vd4Q5YgaUAP0QybD8au7c30jkFBXHFJPTMexNuVqoW776UVRopOpRTSSP4lu9q7P
Lj1U41UoiydQ09RzXrpfSCgrDDBKPYxaVEvrjCzew9ALEMZZQzuAC6SrH0MKTenq
w1c8QN2P5/frPbWpi6MZDtGlBgNwqI65dwKawj3syfGH2FA2Hc6lBibAV/NLhtFM
nAvM6WzIBQmcJexTM3CnlCpPH638943YcQa8V+g6BcLj/L/pdGcFP5vJwnVxzai9
JAarK6Us8nnqGd10zUJoICpGJA03Nd7pgY93fFqu/cb9t6w0MMj5ng==
=50Eb
-----END PGP PUBLIC KEY BLOCK-----
Additional Information:
- https://linuxmint.com/verify.php

Edited by hollowface, 12 June 2016 - 08:11 PM.


#3 Guest_hollowface_*

Guest_hollowface_*

  • Guests
  • OFFLINE
  •  

Posted 12 June 2016 - 07:38 PM

For some reason my first post is getting extra blank lines added. Anyone know how I can stop that? It won't verify like this.

EDIT: Fixed. It's displaying correctly now, and will verify. I tested.

Edited by hollowface, 12 June 2016 - 07:59 PM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users