{"thread":{"id":"55041","subject":"How to Verify Git GPG Signed Downloads?","startedAt":"2021-01-24T16:50:15Z","lastAt":"2021-01-25T01:05:04Z","messageCount":5,"participants":["Brooke Kuhlmann","Jason Pyeron","brian m. carlson","Junio C Hamano"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"415163","messageId":"B6DFB74D-A722-4DBD-A4B2-562604B21CCB@alchemists.io","threadId":"55041","inReplyTo":null,"subject":"How to Verify Git GPG Signed Downloads?","fromName":"Brooke Kuhlmann","fromEmail":"brooke@alchemists.io","sentAt":"2021-01-24T16:49:02Z","receivedAt":"2021-01-24T16:50:15Z","isPatch":false,"sender":{"key":"brooke@alchemists.io","avatar":"https://gravatar.com/avatar/4bd27d52fe87760d2bde1d384f0139eb81013709a0cf27ce654d48a7852727fa?d=mp&s=160"},"body":"Hello, I'm trying to figure out how to obtain the public key used to encrypt the Git file downloads. I put together a gist that explains the problem and question in detail here:\n\nhttps://gist.github.com/bkuhlmann/684b74d25d83d52df8d0caeb6219aa15\n\nIf anyone has any advice on how to make this possible, it would be greatly appreciated.\n\nThanks,\nBrooke\n\n"},{"id":"415178","messageId":"022601d6f27a$58a97200$09fc5600$@pdinc.us","threadId":"55041","inReplyTo":"B6DFB74D-A722-4DBD-A4B2-562604B21CCB@alchemists.io","subject":"RE: How to Verify Git GPG Signed Downloads?","fromName":"Jason Pyeron","fromEmail":"jpyeron@pdinc.us","sentAt":"2021-01-24T17:57:13Z","receivedAt":"2021-01-24T17:58:12Z","isPatch":false,"sender":{"key":"jpyeron@pdinc.us","avatar":"https://gravatar.com/avatar/c2e53452caa53d940768a1ffc9cf76196d851b9b534b7a39cd39852a70a0508f?d=mp&s=160"},"body":"> From: Brooke Kuhlmann\n> Sent: Sunday, January 24, 2021 11:49 AM\n> \n> Hello, I'm trying to figure out how to obtain the public key used to \n> encrypt \n\nDo you mean sign?\n\n> the Git file\n> downloads. I put together a gist that explains the problem and question in detail here:\n> \n> https://gist.github.com/bkuhlmann/684b74d25d83d52df8d0caeb6219aa15\n\nPlease don’t post links to questions, pasting your content inline here:\n\n> Problem\n> When attempting to download a Git version, it would be nice to verify the signature of the download by running the following:\n>\n> curl --remote-name https://mirrors.edge.kernel.org/pub/software/scm/git/git-2.30.0.tar.gz\n> curl --remote-name https://mirrors.edge.kernel.org/pub/software/scm/git/git-2.30.0.tar.sign\n> gpg --verify git-2.30.0.tar.sign git-2.30.0.tar.gz\n> Only problem is that the last line of the above throws the following error:\n>\n> gpg: Signature made Sun Dec 27 23:12:30 2020 MST\n> gpg:                using RSA key E1F036B1FEE7221FC778ECEFB0B5E88696AFE6CB\n> gpg: Can't check signature: No public key\n> I tried using the following solutions to no avail:\n\n$ gpg --recv-keys 96AFE6CB\ngpg: requesting key 96AFE6CB from hkp server keys.gnupg.net\ngpg: key 713660A7: \"Junio C Hamano <gitster@pobox.com>\" 59 new signatures\ngpg: key 713660A7: \"Junio C Hamano <gitster@pobox.com>\" 2 new subkeys\ngpg: no ultimately trusted keys found\ngpg: Total number processed: 1\ngpg:            new subkeys: 2\ngpg:         new signatures: 59\n\n$ gpg --verify -v git-2.30.0.tar.sign git-2.30.0.tar.gz\ngpg: Signature made Mon Dec 28 01:12:30 2020 EST using RSA key ID 96AFE6CB\ngpg: NOTE: signature key 96AFE6CB expired Sun Jul 26 13:41:24 2020 EDT\ngpg: NOTE: signature key B3F7CAC9 expired Sun Jul 26 13:41:42 2020 EDT\ngpg: using subkey 96AFE6CB instead of primary key 713660A7\ngpg: NOTE: signature key 96AFE6CB expired Sun Jul 26 13:41:24 2020 EDT\ngpg: NOTE: signature key 96AFE6CB expired Sun Jul 26 13:41:24 2020 EDT\ngpg: NOTE: signature key B3F7CAC9 expired Sun Jul 26 13:41:42 2020 EDT\ngpg: using PGP trust model\ngpg: BAD signature from \"Junio C Hamano <gitster@pobox.com>\"\ngpg: binary signature, digest algorithm SHA256\n\n$ gpg --list-keys -v 96AFE6CB\ngpg: using PGP trust model\ngpg: NOTE: signature key 96AFE6CB expired Sun Jul 26 13:41:24 2020 EDT\ngpg: NOTE: signature key B3F7CAC9 expired Sun Jul 26 13:41:42 2020 EDT\npub   4096R/713660A7 2011-10-01\nuid                  Junio C Hamano <gitster@pobox.com>\nuid                  Junio C Hamano <junio@pobox.com>\nuid                  Junio C Hamano <jch@google.com>\nsub   4096R/96AFE6CB 2011-10-03 [expired: 2020-07-26]\nsub   4096R/833262C4 2011-10-01\nsub   4096R/B3F7CAC9 2014-09-20 [expired: 2020-07-26]\n\nIt is possible that Junio forgot to push his refreshed public key.\n\n>\n> gpg --locate-keys torvalds@kernel.org gregkh@kernel.org committer@example.com discord@example.net gitster@pobox.com\n> gpg --import <file> # <= Need a file to import but where does one obtain the public key?\n> I also tried importing only the public keys from the Git repository via the following files without any luck either:\n>\n> t/lib-gpg/keyring.gpg\n> contrib/credential/netrc/test.git-config-gpg\n> contrib/credential/netrc/test.netrc.gpg\n> contrib/credential/netrc/test.command-option-gpg\n> Question\n> How does one figure out how to obtain the public keys for which the Git downloads were signed?\n> \n> If anyone has any advice on how to make this possible, it would be greatly appreciated.\n> \n> Thanks,\n> Brooke\n> \n\n\n"},{"id":"415181","messageId":"YA3nwFcYz4tbhrlO@camp.crustytoothpaste.net","threadId":"55041","inReplyTo":"022601d6f27a$58a97200$09fc5600$@pdinc.us","subject":"Re: How to Verify Git GPG Signed Downloads?","fromName":"brian m. carlson","fromEmail":"sandals@crustytoothpaste.net","sentAt":"2021-01-24T21:33:52Z","receivedAt":"2021-01-24T21:34:55Z","isPatch":false,"sender":{"key":"sandals@crustytoothpaste.net","avatar":"https://avatars.githubusercontent.com/u/497054?v=4"},"body":"On 2021-01-24 at 17:57:13, Jason Pyeron wrote:\n> $ gpg --recv-keys 96AFE6CB\n> gpg: requesting key 96AFE6CB from hkp server keys.gnupg.net\n> gpg: key 713660A7: \"Junio C Hamano <gitster@pobox.com>\" 59 new signatures\n> gpg: key 713660A7: \"Junio C Hamano <gitster@pobox.com>\" 2 new subkeys\n> gpg: no ultimately trusted keys found\n> gpg: Total number processed: 1\n> gpg:            new subkeys: 2\n> gpg:         new signatures: 59\n> \n> $ gpg --verify -v git-2.30.0.tar.sign git-2.30.0.tar.gz\n> gpg: Signature made Mon Dec 28 01:12:30 2020 EST using RSA key ID 96AFE6CB\n> gpg: NOTE: signature key 96AFE6CB expired Sun Jul 26 13:41:24 2020 EDT\n> gpg: NOTE: signature key B3F7CAC9 expired Sun Jul 26 13:41:42 2020 EDT\n> gpg: using subkey 96AFE6CB instead of primary key 713660A7\n> gpg: NOTE: signature key 96AFE6CB expired Sun Jul 26 13:41:24 2020 EDT\n> gpg: NOTE: signature key 96AFE6CB expired Sun Jul 26 13:41:24 2020 EDT\n> gpg: NOTE: signature key B3F7CAC9 expired Sun Jul 26 13:41:42 2020 EDT\n> gpg: using PGP trust model\n> gpg: BAD signature from \"Junio C Hamano <gitster@pobox.com>\"\n> gpg: binary signature, digest algorithm SHA256\n\nThe signature is bad because it's over the uncompressed .tar, not the\n.tar.gz.  There is also a .tar.xz and the signature is the same.  You\ntherefore need to uncompress it first with gunzip.\n\n> $ gpg --list-keys -v 96AFE6CB\n> gpg: using PGP trust model\n> gpg: NOTE: signature key 96AFE6CB expired Sun Jul 26 13:41:24 2020 EDT\n> gpg: NOTE: signature key B3F7CAC9 expired Sun Jul 26 13:41:42 2020 EDT\n> pub   4096R/713660A7 2011-10-01\n> uid                  Junio C Hamano <gitster@pobox.com>\n> uid                  Junio C Hamano <junio@pobox.com>\n> uid                  Junio C Hamano <jch@google.com>\n> sub   4096R/96AFE6CB 2011-10-03 [expired: 2020-07-26]\n> sub   4096R/833262C4 2011-10-01\n> sub   4096R/B3F7CAC9 2014-09-20 [expired: 2020-07-26]\n> \n> It is possible that Junio forgot to push his refreshed public key.\n\nYes, I think that's the case.\n-- \nbrian m. carlson (he/him or they/them)\nHouston, Texas, US\n"},{"id":"415183","messageId":"06be01d6f29f$ae6450a0$0b2cf1e0$@pdinc.us","threadId":"55041","inReplyTo":"YA3nwFcYz4tbhrlO@camp.crustytoothpaste.net","subject":"RE: How to Verify Git GPG Signed Downloads?","fromName":"Jason Pyeron","fromEmail":"jpyeron@pdinc.us","sentAt":"2021-01-24T22:24:28Z","receivedAt":"2021-01-24T22:25:40Z","isPatch":false,"sender":{"key":"jpyeron@pdinc.us","avatar":"https://gravatar.com/avatar/c2e53452caa53d940768a1ffc9cf76196d851b9b534b7a39cd39852a70a0508f?d=mp&s=160"},"body":"> From: brian m. carlson\n> Sent: Sunday, January 24, 2021 4:34 PM\n> \n> On 2021-01-24 at 17:57:13, Jason Pyeron wrote:\n> > $ gpg --recv-keys 96AFE6CB\n> > gpg: requesting key 96AFE6CB from hkp server keys.gnupg.net\n> > gpg: key 713660A7: \"Junio C Hamano <gitster@pobox.com>\" 59 new signatures\n> > gpg: key 713660A7: \"Junio C Hamano <gitster@pobox.com>\" 2 new subkeys\n> > gpg: no ultimately trusted keys found\n> > gpg: Total number processed: 1\n> > gpg:            new subkeys: 2\n> > gpg:         new signatures: 59\n> >\n> > $ gpg --verify -v git-2.30.0.tar.sign git-2.30.0.tar.gz\n> > gpg: Signature made Mon Dec 28 01:12:30 2020 EST using RSA key ID 96AFE6CB\n> > gpg: NOTE: signature key 96AFE6CB expired Sun Jul 26 13:41:24 2020 EDT\n> > gpg: NOTE: signature key B3F7CAC9 expired Sun Jul 26 13:41:42 2020 EDT\n> > gpg: using subkey 96AFE6CB instead of primary key 713660A7\n> > gpg: NOTE: signature key 96AFE6CB expired Sun Jul 26 13:41:24 2020 EDT\n> > gpg: NOTE: signature key 96AFE6CB expired Sun Jul 26 13:41:24 2020 EDT\n> > gpg: NOTE: signature key B3F7CAC9 expired Sun Jul 26 13:41:42 2020 EDT\n> > gpg: using PGP trust model\n> > gpg: BAD signature from \"Junio C Hamano <gitster@pobox.com>\"\n> > gpg: binary signature, digest algorithm SHA256\n> \n> The signature is bad because it's over the uncompressed .tar, not the\n> .tar.gz.  There is also a .tar.xz and the signature is the same.  You\n> therefore need to uncompress it first with gunzip.\n\nSilly me, but maybe there should be a README in that directory, along with the signatures.asc. If not, then it should easily be found on the git-scm site.\n\n$ gpg --verify  git-2.30.0.tar.sign git-2.30.0.tar\ngpg: Signature made Mon Dec 28 01:12:30 2020 EST using RSA key ID 96AFE6CB\ngpg: Good signature from \"Junio C Hamano <gitster@pobox.com>\"\ngpg:                 aka \"Junio C Hamano <junio@pobox.com>\"\ngpg:                 aka \"Junio C Hamano <jch@google.com>\"\ngpg: Note: This key has expired!\nPrimary key fingerprint: 96E0 7AF2 5771 9559 80DA  D100 20D0 4E5A 7136 60A7\n     Subkey fingerprint: E1F0 36B1 FEE7 221F C778  ECEF B0B5 E886 96AF E6CB\n\n> \n> > $ gpg --list-keys -v 96AFE6CB\n> > gpg: using PGP trust model\n> > gpg: NOTE: signature key 96AFE6CB expired Sun Jul 26 13:41:24 2020 EDT\n> > gpg: NOTE: signature key B3F7CAC9 expired Sun Jul 26 13:41:42 2020 EDT\n> > pub   4096R/713660A7 2011-10-01\n> > uid                  Junio C Hamano <gitster@pobox.com>\n> > uid                  Junio C Hamano <junio@pobox.com>\n> > uid                  Junio C Hamano <jch@google.com>\n> > sub   4096R/96AFE6CB 2011-10-03 [expired: 2020-07-26]\n> > sub   4096R/833262C4 2011-10-01\n> > sub   4096R/B3F7CAC9 2014-09-20 [expired: 2020-07-26]\n> >\n> > It is possible that Junio forgot to push his refreshed public key.\n> \n> Yes, I think that's the case.\n\n\n"},{"id":"415186","messageId":"xmqqh7n5zv2b.fsf@gitster.c.googlers.com","threadId":"55041","inReplyTo":"YA3nwFcYz4tbhrlO@camp.crustytoothpaste.net","subject":"Re: How to Verify Git GPG Signed Downloads?","fromName":"Junio C Hamano","fromEmail":"gitster@pobox.com","sentAt":"2021-01-25T01:03:56Z","receivedAt":"2021-01-25T01:05:04Z","isPatch":false,"sender":{"key":"gitster@pobox.com","avatar":"https://avatars.githubusercontent.com/u/54884?v=4"},"body":"\"brian m. carlson\" <sandals@crustytoothpaste.net> writes:\n\n>> $ gpg --list-keys -v 96AFE6CB\n>> gpg: using PGP trust model\n>> gpg: NOTE: signature key 96AFE6CB expired Sun Jul 26 13:41:24 2020 EDT\n>> gpg: NOTE: signature key B3F7CAC9 expired Sun Jul 26 13:41:42 2020 EDT\n>> pub   4096R/713660A7 2011-10-01\n>> uid                  Junio C Hamano <gitster@pobox.com>\n>> uid                  Junio C Hamano <junio@pobox.com>\n>> uid                  Junio C Hamano <jch@google.com>\n>> sub   4096R/96AFE6CB 2011-10-03 [expired: 2020-07-26]\n>> sub   4096R/833262C4 2011-10-01\n>> sub   4096R/B3F7CAC9 2014-09-20 [expired: 2020-07-26]\n>> \n>> It is possible that Junio forgot to push his refreshed public key.\n>\n> Yes, I think that's the case.\n\nHmph, I was fairly sure I pushed it out when I refreshed the expiry\ndate sometime early last year, but apparently it did not go through.\n\nI just tried recv-keys from keys.gnupg.net into a throw-away\nGNUPGHOME and got the output at the end, so it should be OK now.\nSorry about that.\n\n\n$ gpg --list-keys -v 96AFE6CB\ngpg: using pgp trust model\npub   rsa4096 2011-10-01 [SC]\n      96E07AF25771955980DAD10020D04E5A713660A7\nuid           [ unknown] Junio C Hamano <gitster@pobox.com>\nuid           [ unknown] Junio C Hamano <jch@google.com>\nuid           [ unknown] Junio C Hamano <junio@pobox.com>\nsub   rsa4096 2011-10-01 [E]\nsub   rsa4096 2011-10-03 [S] [expires: 2028-01-11]\nsub   rsa4096 2014-09-20 [S] [expires: 2028-01-11]\n"}]}