unofficial mirror of bug-gnu-emacs@gnu.org 
 help / color / mirror / code / Atom feed
From: Richard Kettlewell <rjk@terraraq.uk>
To: Eli Zaretskii <eliz@gnu.org>
Cc: 25572@debbugs.gnu.org
Subject: bug#25572: Signatures on Emacs windows .zip files
Date: Sun, 29 Jan 2017 20:36:15 +0000	[thread overview]
Message-ID: <a0744b27-51f1-305a-0d07-83eac73a4874@terraraq.uk> (raw)
In-Reply-To: <83d1f5y67j.fsf@gnu.org>

On 2017-01-29 20:14, Eli Zaretskii wrote:
>> According to https://www.gnu.org/software/emacs/download.html:
>>
>>     Since the 24.5 release, tarballs are signed with the GPG key from
>>     Nicolas Petton 7C207910, fingerprint 28D3 BED8 51FD F3AB 57FE
>>     F93C 2335 87A4 7C20 7910, which can be found in the GNU keyring.
>>
>> However the windows .zip files on http://ftp.gnu.org/gnu/emacs are
>> signed with some other key:
>>
>> $ gpg2 --verify emacs-25.1-2-x86_64-w64-mingw32.zip.sig
>> gpg: Signature made 11/29/16 19:54:09 GMT Standard Time using DSA key ID
>> 60C3B396
>> gpg: Good signature from "Phillip Lord <phillip.lord@russet.org.uk>"
>> gpg:                 aka "Phillip Lord <p.lord@russet.org.uk>"
>> gpg:                 aka "Phillip Lord <p.lord@hgmp.mrc.ac.uk>"
>> gpg:                 aka "Phillip Lord <phillip.lord@newcastle.ac.uk>"
>> gpg: WARNING: This key is not certified with a trusted signature!
>> gpg:          There is no indication that the signature belongs to the
>> owner.
>> Primary key fingerprint: 8352 2404 7598 ECBC 61A1  DA34 5FE9 658D 60C3 B396
> 
> That's because the zip files with Windows binaries were produced by
> Phillip.

Thankyou for replying. The point is: how do I verify that I have a
legitimate download of the GNU Emacs Windows binaries?

I have an informal trust path to
28D3BED851FDF3AB57FEF93C233587A47C207910 because https://www.gnu.org
mentions it. No such statement exists about
835224047598ECBC61A1DA345FE9658D60C3B396.

> Why is that a bug?

The web page told me to send comments to bug-gnu-emacs@gnu.org, and so
here we are.

Is there some more appropriate reporting channel?

ttfn/rjk






  reply	other threads:[~2017-01-29 20:36 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2017-01-29 11:48 bug#25572: Signatures on Emacs windows .zip files Richard Kettlewell
2017-01-29 20:14 ` Eli Zaretskii
2017-01-29 20:36   ` Richard Kettlewell [this message]
2017-01-29 21:14   ` Phillip Lord
2017-01-30 22:32     ` Glenn Morris
2017-02-06 10:37       ` Phillip Lord
2017-02-06 13:09       ` Nicolas Petton
2017-02-07  4:37         ` Glenn Morris
2017-01-29 20:56 ` Phillip Lord
2017-01-29 21:37   ` Richard Kettlewell
2017-02-06 13:04   ` Nicolas Petton
2017-11-19 14:11 ` Richard Kettlewell

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

  List information: https://www.gnu.org/software/emacs/

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=a0744b27-51f1-305a-0d07-83eac73a4874@terraraq.uk \
    --to=rjk@terraraq.uk \
    --cc=25572@debbugs.gnu.org \
    --cc=eliz@gnu.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
Code repositories for project(s) associated with this public inbox

	https://git.savannah.gnu.org/cgit/emacs.git

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).