Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
[solved] gpg: WARNING: not a detached signature ?
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Installing Gentoo
View previous topic :: View next topic  
Author Message
toralf
Developer
Developer


Joined: 01 Feb 2004
Posts: 3691
Location: Hamburg

PostPosted: Mon Feb 22, 2016 1:03 pm    Post subject: [solved] gpg: WARNING: not a detached signature ? Reply with quote

Code:
# ls -l stage3-amd64-20160218.tar.bz2*
-rw-r--r-- 1 root root 250588707 Feb 19 09:25 stage3-amd64-20160218.tar.bz2
-rw-r--r-- 1 root root       720 Feb 19 09:25 stage3-amd64-20160218.tar.bz2.DIGESTS
-rw-r--r-- 1 root root      1588 Feb 19 15:43 stage3-amd64-20160218.tar.bz2.DIGESTS.asc

# gpg --verify stage3-amd64-20160211.tar.bz2.DIGESTS.asc
gpg: Signature made Fri 12 Feb 2016 09:25:58 AM CET using RSA key ID 2D182910
gpg: Good signature from "Gentoo Linux Release Engineering (Automated Weekly Release Key) <releng@gentoo.org>" [unknown]
gpg: WARNING: This key is not certified with a trusted signature!
gpg:          There is no indication that the signature belongs to the owner.
Primary key fingerprint: 13EB BDBE DE7A 1277 5DFD  B1BA BB57 2E0E 2D18 2910
gpg: WARNING: not a detached signature; file 'stage3-amd64-20160211.tar.bz2.DIGESTS' was NOT verified!


Last edited by toralf on Mon Feb 22, 2016 7:52 pm; edited 1 time in total
Back to top
View user's profile Send private message
khayyam
Watchman
Watchman


Joined: 07 Jun 2012
Posts: 6228
Location: Room 101

PostPosted: Mon Feb 22, 2016 1:27 pm    Post subject: Re: gpg: WARNING: not a detached signature ? Reply with quote

toralf wrote:
Code:
gpg: WARNING: not a detached signature; file 'stage3-amd64-20160211.tar.bz2.DIGESTS' was NOT verified!

toralf ... you want it to verify the DIGEST used for verifying the sha checksum?

Code:
# rm -f stage3-amd64-20160211.tar.bz2.DIGESTS
# gpg --verify stage3-amd64-20160211.tar.bz2.DIGESTS.asc
# sha512sum -c stage3-amd64-20160211.tar.bz2.DIGESTS.asc

HTH & best ... khay
Back to top
View user's profile Send private message
toralf
Developer
Developer


Joined: 01 Feb 2004
Posts: 3691
Location: Hamburg

PostPosted: Mon Feb 22, 2016 1:33 pm    Post subject: Reply with quote

I just like to verify that the stage3 is correct as described here : https://wiki.gentoo.org/wiki/Handbook:AMD64/Installation/Stage#Downloading_the_stage_tarball
Code:
root #gpg --verify stage3-amd64-<release>.tar.bz2.DIGESTS.asc
Back to top
View user's profile Send private message
khayyam
Watchman
Watchman


Joined: 07 Jun 2012
Posts: 6228
Location: Room 101

PostPosted: Mon Feb 22, 2016 6:48 pm    Post subject: Reply with quote

toralf wrote:
I just like to verify that the stage3 is correct as described here

toralf ... yes, and that's why I asked why might think you need the *.DIGEST, or to verify it, and why I removed it in the above code block. In the above linked section of the handbook it states:

Quote:
* A .DIGESTS.asc file that, like the .DIGESTS file, contains checksums of the stage file in different algorithms, but is also cryptographically signed to ensure it is provided by the Gentoo project.

So, if you have the *.DIGESTS.asc the *.DIGESTS isn't required, and obviously gpg complains that it can't verify it (as it matches the name of the *.asc, and so gpg takes it as one of the files it should treat as "signed data").

best ... khay
Back to top
View user's profile Send private message
toralf
Developer
Developer


Joined: 01 Feb 2004
Posts: 3691
Location: Hamburg

PostPosted: Mon Feb 22, 2016 7:51 pm    Post subject: Reply with quote

indeed, now I undersood it :
Code:
# rm  stage3-amd64-20160211.tar.bz2.DIGESTS

# gpg --verify stage3-amd64-20160211.tar.bz2.DIGESTS.asc
gpg: Signature made Fri 12 Feb 2016 09:25:58 AM CET using RSA key ID 2D182910
gpg: Good signature from "Gentoo Linux Release Engineering (Automated Weekly Release Key) <releng@gentoo.org>" [unknown]
gpg: WARNING: This key is not certified with a trusted signature!
gpg:          There is no indication that the signature belongs to the owner.
Primary key fingerprint: 13EB BDBE DE7A 1277 5DFD  B1BA BB57 2E0E 2D18 2910
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Installing Gentoo All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum