On 01/01/2018 11:44 AM, Kyle Breneman wrote:
I have successfully verified the fingerprint for the Qubes Master Signing Key.
I have verified the Release 3 ISO signature using the Qubes Release 3 Signing
Key. How do I verify that the Release 3 signing key is good? Do I somehow use
the Qubes Master Signing Key to verify the authenticity of the Release 3
Signing Key? If so, please explain how to do this with gpg4win? Thanks!
After you import both the master and signing keys, you can check them
with 'gpg --check-sigs' which should have output like this:
pub rsa4096 2017-03-06 [SC]
uid [ unknown] Qubes OS Release 4 Signing Key
sig!3 1848792F9E2795E9 2017-03-06 Qubes OS Release 4 Signing Key
sig! DDFA1A3E36879494 2017-03-08 Qubes Master Signing Key
(I have the Qubes 4 key but its otherwise the same.)
This lists the Qubes master key under the uid for the Qubes release key,
showing the release key has been signed by the master. The exclamation
mark after "sig" means the signature has been verified as good.
Chris Laprise, tas...@posteo.net
PGP: BEE2 20C5 356E 764A 73EB 4AB3 1DC4 D106 F07F 1886
You received this message because you are subscribed to the Google Groups
To unsubscribe from this group and stop receiving emails from it, send an email
To post to this group, send email to firstname.lastname@example.org.
To view this discussion on the web visit
For more options, visit https://groups.google.com/d/optout.