On trying to verify KNOPPIX_V5.1.1DVD-2007-01-04-EN.iso.md5.asc I also get DSA key ID 57E37087 - not the expected one. Would really like to know what's going on here...
I have downloaded KNOPPIX_V4.0.2DVD-2005-09-23-EN.iso and the corresponding
md5, sha1, and asc files via:
http://knopper.net/knoppix-mirrors/d...de/knoppix-dvd
When I use gpg, I get this information (after I have retreived the identified key):
gpg: Signature made Sat Sep 24 15:59:30 2005 NZST using DSA key ID 57E37087
gpg: Good signature from "Klaus Knopper <[email protected]>"
gpg: aka "Klaus Knopper <[email protected]>"
gpg: aka "Klaus Knopper <[email protected]>"
gpg: WARNING: This key is not certified with a trusted signature!
gpg: There is no indication that the signature belongs to the owner.
Primary key fingerprint: 0E57 3DA0 F139 69EF 1DD5 ACAA 3798 E3D7 57E3 7087
Now, the Downloading FAQ leads me to expect a key ID of BA8F038D.
So, what is the story here?
On trying to verify KNOPPIX_V5.1.1DVD-2007-01-04-EN.iso.md5.asc I also get DSA key ID 57E37087 - not the expected one. Would really like to know what's going on here...
going to keyserver.net and looking for knoppix lists:
Klaus Knopper <[email protected]> 0x57E37087 1024/1024 2000/05/06 Never
So apparently somebody claiming to be Klaus registered that key back in 2000. Still it's odd that there are so few references to that key on the net.
In my gpg keyring, it appears that
key BA8F038D is signed by key 57E37087 ;
but key 57E37087 is not signed by key BA8F038D.
Moreover,
$ gpg --verify KNOPPIX_V5.1.1DVD-2007-01-04-EN.iso.md5.asc
gpg: Signature made ven 05 gen 2007 04:15:35 CET using DSA key ID 57E37087
gpg: Good signature from "Klaus Knopper <[email protected]>"
gpg: aka "Klaus Knopper <[email protected]>"
gpg: aka "Klaus Knopper <[email protected]>"
gpg: WARNING: This key is not certified with a trusted signature!
gpg: There is no indication that the signature belongs to the owner.
Primary key fingerprint: 0E57 3DA0 F139 69EF 1DD5 ACAA 3798 E3D7 57E3 7087
So, verifying the downloaded image by using key 57E37087 does not provide any security at all.
I could imagine a situation like this:
Mr Knopper builds Knoppix and signs the image with key BA8F038D ;
the attacker creates a key 57E37087 and it signs BA8F038D with it,
the attacker tampers Knoppix and signs with 57E37087.
I know this sounds a bit paranoid; but I will feel safer if Mr Knopper may post the gpg fingerprint of both keys in the FAQ.

Lenovo ThinkPad T460 Intel Core i5-6300U @ 2.40 GHz 8GB 128GB SSD Windows 10 Pro
$89.95
Lenovo ThinkPad L15 Gen 3 15.6" 16GB, Thunder Black
$242.00
Lenovo Thinkpad E15 15.6" Laptop i5/i3 8GB RAM Up to 1TB SSD HDD Tested Working
$136.55
Lenovo ThinkPad L14 Gen 3 Laptop 14” FHD Core i5 12th 16GB RAM 512GB SSD Win 11
$374.99
LENOVO THINKPAD T14s GEN 2a Ryzen 7 PRO 5850U 1.9GHz 16GB 256GB TOUCH - NO OS
$299.95
Lenovo Thinkpad T14 Gen 2i 14" 16GB 512GB, Black
$313.00
LENOVO ThinkPad E15 Gen 3 AMD Ryzen 5 5500U 8GB RAM 256GB NVMe Win11P
$189.98
Lenovo LOQ 15 15.6" FHD 144Hz 8-Core i5-12450HX 16GB 512GB SSD GeForce RTX 4050
$760.00
Lenovo Thinkpad E15 Gen 2 8GB RAM 256GB SSD Intel Core [email protected] Laptop
$220.36
Lenovo ThinkPad L15 Gen 3 15.6" 16GB, Thunder Black
$242.00