|
|
Log in / Subscribe / Register

I can't verify this signature

I can't verify this signature

Posted Jun 19, 2024 17:06 UTC (Wed) by bahner (guest, #35608)
Parent article: Libgcrypt 1.11.0 released

As the subject says: I can't verify the text. I went to https://lists.gnupg.org/pipermail/gnupg-announce/2024q2/0... for the "original" too, but I can't verify that either.

Anyone with verification FU here to confirm or tell me howto?


to post comments

I can't verify this signature

Posted Jun 22, 2024 5:33 UTC (Sat) by ametlwn (subscriber, #10544) [Link]

You need the original MIME-encoded version of the mail to successfully verify manually i.e.

to-verify-txt
8X---------
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable

Hello!

We are pleased to announce the availability of Libgcrypt version 1.11.0.
[...]

=2D-=20
The pioneers of a warless world are the youth that
refuse military service. - A. Einstein
8X---------

(Tested with the version on gmane, which is available via NNTP.)

The signature on the tarball verifies as documented:
ametzler@argenau:/tmp$ gpg --verify --keyring /tmp/signature_key.asc libgcrypt-1.11.0.tar.bz2.sig libgcrypt-1.11.0.tar.bz2
gpg: Signature made Mi 19 Jun 2024 11:31:18 CEST
gpg: using EDDSA key 6DAA6E64A76D2840571B4902528897B826403ADA
gpg: Good signature from "Werner Koch (dist signing 2020)" [unknown]
gpg: WARNING: This key is not certified with a trusted signature!
gpg: There is no indication that the signature belongs to the owner.
Primary key fingerprint: 6DAA 6E64 A76D 2840 571B 4902 5288 97B8 2640 3ADA


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds