-
key ID 57E37087 vs BA8F038D
I have downloaded KNOPPIX_V4.0.2DVD-2005-09-23-EN.iso and the corresponding
md5, sha1, and asc files via:
http://knopper.net/knoppix-mirrors/d...de/knoppix-dvd
When I use gpg, I get this information (after I have retreived the identified key):
gpg: Signature made Sat Sep 24 15:59:30 2005 NZST using DSA key ID 57E37087
gpg: Good signature from "Klaus Knopper <[email protected]>"
gpg: aka "Klaus Knopper <[email protected]>"
gpg: aka "Klaus Knopper <[email protected]>"
gpg: WARNING: This key is not certified with a trusted signature!
gpg: There is no indication that the signature belongs to the owner.
Primary key fingerprint: 0E57 3DA0 F139 69EF 1DD5 ACAA 3798 E3D7 57E3 7087
Now, the Downloading FAQ leads me to expect a key ID of BA8F038D.
So, what is the story here?
-
I have the same problem - is this ISO corrupt?
On trying to verify KNOPPIX_V5.1.1DVD-2007-01-04-EN.iso.md5.asc I also get DSA key ID 57E37087 - not the expected one. Would really like to know what's going on here...
-
Further looking suggests it might be okay
going to keyserver.net and looking for knoppix lists:
Klaus Knopper <[email protected]> 0x57E37087 1024/1024 2000/05/06 Never
So apparently somebody claiming to be Klaus registered that key back in 2000. Still it's odd that there are so few references to that key on the net.
-
being a bit paranoid...
In my gpg keyring, it appears that
key BA8F038D is signed by key 57E37087 ;
but key 57E37087 is not signed by key BA8F038D.
Moreover,
$ gpg --verify KNOPPIX_V5.1.1DVD-2007-01-04-EN.iso.md5.asc
gpg: Signature made ven 05 gen 2007 04:15:35 CET using DSA key ID 57E37087
gpg: Good signature from "Klaus Knopper <[email protected]>"
gpg: aka "Klaus Knopper <[email protected]>"
gpg: aka "Klaus Knopper <[email protected]>"
gpg: WARNING: This key is not certified with a trusted signature!
gpg: There is no indication that the signature belongs to the owner.
Primary key fingerprint: 0E57 3DA0 F139 69EF 1DD5 ACAA 3798 E3D7 57E3 7087
So, verifying the downloaded image by using key 57E37087 does not provide any security at all.
I could imagine a situation like this:
Mr Knopper builds Knoppix and signs the image with key BA8F038D ;
the attacker creates a key 57E37087 and it signs BA8F038D with it,
the attacker tampers Knoppix and signs with 57E37087.
I know this sounds a bit paranoid; but I will feel safer if Mr Knopper may post the gpg fingerprint of both keys in the FAQ.
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules

Samsung M323R2GA3EB0-CWM0L 32GB (2x16GB) RAM DDR5 5600MHz PC5-5600B-UA0
$374.99

Corsair Vengeance LPX 128GB (4 x 32GB) (DDR4-3600) Memory (CMK64GX4M2D3600C18)
$899.00

SK Hynix 2207 32GB (2x16GB) RAM DDR4 3200MHz PC4-3200AA-SA2-13
$114.99

RAMAXEL Lenovo 32GB LPDDR5X CAMM2 7500MHz Laptop RAM | UNTESTED
$445.00

Corsair Vengeance LPX 64GB (2x32GB) DDR4 3200MHz Desktop Kit CMK64GX4M2E3200C16
$405.00

DDR4 Laptop RAM 4GB 8GB 16GB 32GB 2400 2666 3200 Samsung Hynix
$31.00

Crucial DDR3L 16GB 2 x 8GB 1600 MHz PC3L-12800 Laptop RAM Sodimm Memory 1.35V
$41.00

A-Tech 8GB DDR3 1600 PC3-12800 Laptop SODIMM 204-Pin Memory RAM PC3L DDR3L 1x 8G
$21.68

Lot Of 50 8GB DDR4 RAM PC4-2666V-UA2 DIMM Desktop Memory Mixed Brands TESTED
$1750.00

Corsair Vengeance LP White 16GB Kit (2x8GB) DDR3L 1600MHz RAM CML8GX3M2A1600C9W
$40.00