Autenticity control (gpg --verify SHA512SUMS.sign SHA512SUMS.txt):
[...]
gpg: utilizzando la chiave RSA DF9B9C49EAA9298432589D76DA87E80D6294BE9B
gpg: Firma BAD da "Debian CD signing key <debian-cd@lists.debian.org>"
So... first step:
PS C:\Users\CP> gpg --keyserver hkps://keyring.debian.org --recv-keys DF9B9C49EAA9298432589D76DA87E80D6294BE9B
[...]
Second step:
PS C:\Users\CP\Documents\Linux\Debian12.10.0\VersioneHTTP>
gpg --verify SHA512SUMS.sign SHA512SUMS.txt
gpg: Firma effettuata 03/15/25 21:33:08 ora solare Europa occidentale
gpg: utilizzando la chiave RSA DF9B9C49EAA9298432589D76DA87E80D6294BE9B
third step:
PS C:\Users\CP\Documents\Linux\Debian12.10.0\VersioneHTTP> gpg --output debian-key.asc --export DF9B9C49EAA9298432589D76DA87E80D6294BE9B
Il file 'debian-key.asc' esiste. Sovrascrivere? (y/N) y
to import it inside Kleopatra...and... bad signature inside Kleopatra!
Inside console:
PS C:\Users\CP\Documents\Linux\Debian12.10.0\VersioneHTTP> gpg --verify SHA512SUMS.sign SHA512SUMS.txt
gpg: Firma effettuata 03/15/25 21:33:08 ora solare Europa occidentale
gpg: utilizzando la chiave RSA DF9B9C49EAA9298432589D76DA87E80D6294BE9B
gpg: Firma BAD da "Debian CD signing key <debian-cd@lists.debian.org>" [sconosciuto]
Where is the mistake?
3D0BA303805111F651A88D96FC64867FFC678E43F3756F5F91B24A810D91015E459... C:\Users\CP\Documents\Linux\Debian12.10.0\VersioneHTTP\SHA512SUMS.txt
58B5434926A9E5F7BA27FA32CD19B4379658945646549D6ACD3EC9A9368FFFACDAC... C:\Users\CP\Documents\Linux\Debian12.10.0\VersioneHTTP\SHA512SUMS.sign
gpg: Firma effettuata 03/15/25 21:33:08 ora solare Europa occidentale gpg: utilizzando la chiave RSA DF9B9C49EAA9298432589D76DA87E80D6294BE9B
Did this second-step run succeed ?
It seems that the decisive message line is missing.
What message?
The content of these links, seen now, is the following: cb089def0684fd93c9c2fbe45fd16ecc809c949a6fd0c91ee199faefe7d4b82b64658a264a13109d59f1a40ac3080be2f7bd3d8bf3e9cdf509add6d72576a79b debian-12.10.0-amd64-netinst.iso
71d4c4e2ea7b617362875a74eb007308ae577ebe4b02ffeb626f1d12eaf412567d1d1816dbdbbb84cfaa38a205c13abf317ec227e5b2df9c982979698909889c debian-edu-12.10.0-amd64-netinst.iso
269e64d2a379429905cf95191036cc53fdc148c624af68386d3a238f5fe2c5b03e3732706eaac175303b1fe327f691dc50faf8d65665781d6bcbbabf072559fa debian-mac-12.10.0-amd64-netinst.iso
gpg: Firma valida da "Debian CD signing key <debian-cd@lists.debian.org>"
gpg: ATTENZIONE: questa chiave non è certificata con una firma fidata!
gpg: Non ci sono indicazioni che la firma appartenga al proprietario.
Impronta digitale della chiave primaria: DF9B 9C49 EAA9 2984 3258 9D76 DA87 E80D 6294 BE9B
Conclusion: I am really very perplexed by the outcome of this authenticity check of the file debian-12.10.0-amd64-netinst.iso: all these commands and attempts to arrive at what? To the sentence "WARNING: this key is not certified with a trusted signature!There is no indication that the signature belongs to the owner."????
Or is there still something to clarify regarding the selection of the key?
So now the authenticity check is complete and the authenticity is completely sure?
Sysop: | Keyop |
---|---|
Location: | Huddersfield, West Yorkshire, UK |
Users: | 546 |
Nodes: | 16 (0 / 16) |
Uptime: | 163:49:38 |
Calls: | 10,385 |
Calls today: | 2 |
Files: | 14,057 |
Messages: | 6,416,513 |