On 2020-04-21 1:41 p.m., David Sommerseth wrote:
> On 21/04/2020 18:32, Simon Deziel wrote:
>> Hello,
>>
>> I cannot validate the Windows exe files [1] and [2] using the key
>> advertised in [3].
>>
>> $ gpg --verify openvpn-install-2.4.9-I601-Win7.exe.asc
>> gpg: assuming signed data in 'openvpn-install-2.4.9-I601-Win7.exe'
>> gpg: Signature made Fri 17 Apr 2020 07:25:11 AM EDT
>> gpg:                using RSA key 333D46306CF9D9F1F630DB8D96AEC408005D6BB4
>> gpg: Can't check signature: No public key
>>
>> $ gpg --verify openvpn-install-2.4.9-I601-Win10.exe.asc
>> gpg: assuming signed data in 'openvpn-install-2.4.9-I601-Win10.exe'
>> gpg: Signature made Fri 17 Apr 2020 07:25:00 AM EDT
>> gpg:                using RSA key 333D46306CF9D9F1F630DB8D96AEC408005D6BB4
>> gpg: Can't check signature: No public key
>>
>>
>> $ gpg --list-keys F554A3687412CFFEBDEFE0A312F5F7B42F2B01E7
>> pub   rsa4096/0x12F5F7B42F2B01E7 2017-02-09 [SC] [expires: 2027-02-07]
>>       Key fingerprint = F554 A368 7412 CFFE BDEF  E0A3 12F5 F7B4 2F2B 01E7
>> uid                   [ unknown] OpenVPN - Security Mailing List
>> <secur...@openvpn.net>
>>
>>
>> Did I download the right files?
>>
>> $ sha256sum openvpn-install-2.4.9-I601-Win*
>> 4f95a674c3ffafd85062df995a182cfb57ca56d96084472a48a65c546c815f0c
>> openvpn-install-2.4.9-I601-Win10.exe
>> 340a6b917c5358a18e4ed283669e8d59073720184dba2d1f2965512c9cac18ad
>> openvpn-install-2.4.9-I601-Win10.exe.asc
>> 495754e6f3e40a056b947d496729f3ba78aaf0458d80ff08991c27bddf386139
>> openvpn-install-2.4.9-I601-Win7.exe
>> b15e4b34756446589cc609d5d08fe5daba98c34463135b7abfab1538722c4c4e
>> openvpn-install-2.4.9-I601-Win7.exe.asc
> 
> 
> Try refreshing the PGP keys.  We pushed out new keys in early March, but seems
> the web page was not updated.
> 
>     $ gpg --refresh-keys F554A3687412CFFEBDEFE0A312F5F7B42F2B01E7
> 
> This should do the proper key update and the verification should work just
> fine.  We always publish the security public key to key servers whenever they
> are updated.

I did a refresh prior to posting and did another just now, no change:

$ gpg --refresh-keys F554A3687412CFFEBDEFE0A312F5F7B42F2B01E7
gpg: refreshing 1 key from hkps://keys.openpgp.org
gpg: key 0x12F5F7B42F2B01E7: "OpenVPN - Security Mailing List
<secur...@openvpn.net>" not changed
gpg: Total number processed: 1
gpg:              unchanged: 1

Are you publishing to keys.openpgp.org or should I query another server?

Thanks,
Simon

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
Openvpn-users mailing list
Openvpn-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/openvpn-users

Reply via email to