On trying to verify KNOPPIX_V5.1.1DVD-2007-01-04-EN.iso.md5.asc I also get DSA key ID 57E37087 - not the expected one. Would really like to know what's going on here...
I have downloaded KNOPPIX_V4.0.2DVD-2005-09-23-EN.iso and the corresponding
md5, sha1, and asc files via:
http://knopper.net/knoppix-mirrors/d...de/knoppix-dvd
When I use gpg, I get this information (after I have retreived the identified key):
gpg: Signature made Sat Sep 24 15:59:30 2005 NZST using DSA key ID 57E37087
gpg: Good signature from "Klaus Knopper <[email protected]>"
gpg: aka "Klaus Knopper <[email protected]>"
gpg: aka "Klaus Knopper <[email protected]>"
gpg: WARNING: This key is not certified with a trusted signature!
gpg: There is no indication that the signature belongs to the owner.
Primary key fingerprint: 0E57 3DA0 F139 69EF 1DD5 ACAA 3798 E3D7 57E3 7087
Now, the Downloading FAQ leads me to expect a key ID of BA8F038D.
So, what is the story here?
On trying to verify KNOPPIX_V5.1.1DVD-2007-01-04-EN.iso.md5.asc I also get DSA key ID 57E37087 - not the expected one. Would really like to know what's going on here...
going to keyserver.net and looking for knoppix lists:
Klaus Knopper <[email protected]> 0x57E37087 1024/1024 2000/05/06 Never
So apparently somebody claiming to be Klaus registered that key back in 2000. Still it's odd that there are so few references to that key on the net.
In my gpg keyring, it appears that
key BA8F038D is signed by key 57E37087 ;
but key 57E37087 is not signed by key BA8F038D.
Moreover,
$ gpg --verify KNOPPIX_V5.1.1DVD-2007-01-04-EN.iso.md5.asc
gpg: Signature made ven 05 gen 2007 04:15:35 CET using DSA key ID 57E37087
gpg: Good signature from "Klaus Knopper <[email protected]>"
gpg: aka "Klaus Knopper <[email protected]>"
gpg: aka "Klaus Knopper <[email protected]>"
gpg: WARNING: This key is not certified with a trusted signature!
gpg: There is no indication that the signature belongs to the owner.
Primary key fingerprint: 0E57 3DA0 F139 69EF 1DD5 ACAA 3798 E3D7 57E3 7087
So, verifying the downloaded image by using key 57E37087 does not provide any security at all.
I could imagine a situation like this:
Mr Knopper builds Knoppix and signs the image with key BA8F038D ;
the attacker creates a key 57E37087 and it signs BA8F038D with it,
the attacker tampers Knoppix and signs with 57E37087.
I know this sounds a bit paranoid; but I will feel safer if Mr Knopper may post the gpg fingerprint of both keys in the FAQ.

Dell Poweredge R720 8SFF 2.5" x Xeon E5-2680 v2 2.8GHz 20-Cores 128gb 4x Trays
$349.99
Dell EMC PowerEdge R440 Xeon silver 4215 2.5GHz 16 GB ram 2x 550W PSU No HDD
$275.00
Dell PowerEdge R730XD Server 2x E5-2695 V4 = 36 Cores H730p 32GB RAM 4x trays
$649.99
Dell Poweredge R720 8SFF 2.5" 2x Xeon E5-2680 v2 2.8GHz 20-Cores 64gb 4x Trays
$259.99
Dell PowerEdge R620 2x Xeon E5-2630 v2 3.1GHz 2.5" 4-BAY 32GB RAM No OS 2x 495w
$174.95
Dell Poweredge R630 2x Xeon E5-2680 v3 2.5ghz 24-Cores / 64gb / Raid / 2x 1Tb
$374.99
Dell PowerEdge R620 Dual Intel Xeon E5-2640 v2 @2.00GHz 192GB RAM No HDD H710P
$250.00
Dell Poweredge R530 Server Dual Xeon E5-2660v3 CPU's 160GB DDR4 Ram NO HDD NO OS
$499.99
Dell PowerEdge R530 2x E5-2630v4 H330 iDRAC8 Port Card Riser No PSU/RAM/HDD
$99.99
DELL R640 10SFF Server 2x Gold 6152 2.1GHz =44 Cores 64GB H730p 4xRJ45
$959.00