On trying to verify KNOPPIX_V5.1.1DVD-2007-01-04-EN.iso.md5.asc I also get DSA key ID 57E37087 - not the expected one. Would really like to know what's going on here...
I have downloaded KNOPPIX_V4.0.2DVD-2005-09-23-EN.iso and the corresponding
md5, sha1, and asc files via:
http://knopper.net/knoppix-mirrors/d...de/knoppix-dvd
When I use gpg, I get this information (after I have retreived the identified key):
gpg: Signature made Sat Sep 24 15:59:30 2005 NZST using DSA key ID 57E37087
gpg: Good signature from "Klaus Knopper <[email protected]>"
gpg: aka "Klaus Knopper <[email protected]>"
gpg: aka "Klaus Knopper <[email protected]>"
gpg: WARNING: This key is not certified with a trusted signature!
gpg: There is no indication that the signature belongs to the owner.
Primary key fingerprint: 0E57 3DA0 F139 69EF 1DD5 ACAA 3798 E3D7 57E3 7087
Now, the Downloading FAQ leads me to expect a key ID of BA8F038D.
So, what is the story here?
On trying to verify KNOPPIX_V5.1.1DVD-2007-01-04-EN.iso.md5.asc I also get DSA key ID 57E37087 - not the expected one. Would really like to know what's going on here...
going to keyserver.net and looking for knoppix lists:
Klaus Knopper <[email protected]> 0x57E37087 1024/1024 2000/05/06 Never
So apparently somebody claiming to be Klaus registered that key back in 2000. Still it's odd that there are so few references to that key on the net.
In my gpg keyring, it appears that
key BA8F038D is signed by key 57E37087 ;
but key 57E37087 is not signed by key BA8F038D.
Moreover,
$ gpg --verify KNOPPIX_V5.1.1DVD-2007-01-04-EN.iso.md5.asc
gpg: Signature made ven 05 gen 2007 04:15:35 CET using DSA key ID 57E37087
gpg: Good signature from "Klaus Knopper <[email protected]>"
gpg: aka "Klaus Knopper <[email protected]>"
gpg: aka "Klaus Knopper <[email protected]>"
gpg: WARNING: This key is not certified with a trusted signature!
gpg: There is no indication that the signature belongs to the owner.
Primary key fingerprint: 0E57 3DA0 F139 69EF 1DD5 ACAA 3798 E3D7 57E3 7087
So, verifying the downloaded image by using key 57E37087 does not provide any security at all.
I could imagine a situation like this:
Mr Knopper builds Knoppix and signs the image with key BA8F038D ;
the attacker creates a key 57E37087 and it signs BA8F038D with it,
the attacker tampers Knoppix and signs with 57E37087.
I know this sounds a bit paranoid; but I will feel safer if Mr Knopper may post the gpg fingerprint of both keys in the FAQ.

Seagate ST500DM009 BarraCuda 500 GB 3.5" SATA III Desktop Hard Drive
$14.99
Seagate 6TB HDD ST6000NM0034 7.2K 3.5" SAS 12Gb/s (NOT FOR PC - FOR SERVER ONLY)
$87.00
Dell EMC WD-HITACHI H5H72101CLAR10T0 10TB 7.2K SAS 12Gb/s SED 3.5in A POH 0-50k
$189.99
Western Digital RE WD4000FYYZ 4TB 7200 RPM 64MB Cache SATA 6Gb/s 3.5" Hard Drive
$129.99
Toshiba 14TB MG07 MG07ACA14TEY 7.2K RPM SATA 6Gb/s 512e 3.5" Enterprise HDD
$299.00
Seagate ST1000VM002 1TB 5900RPM 3.5" SATA 6GB/s HDD Video Hard Drive PC DVR
$24.99
Seagate ST28000NM001C 28TB 256MB 7200RPM 3.5" SATA 6.0Gb/s Enterprise Hard Drive
$669.99
WD Ultrastar DC HC530 14TB SATA 6G 3.5" 7200RPM Enterprise HDD - WUH721414ALE604
$329.99
Western Digital HUS726T4TAL5204 4TB 7.2K SAS 12Gb/s 3.5" 512e HDD NetApp X375A
$49.00
Seagate ST8000NM0075 Enterprise Capacity 3.5 HDD 8TB SAS Hard Drive 8TB EXOS
$184.99