From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.org!.POSTED!not-for-mail From: Richard Kettlewell Newsgroups: gmane.emacs.bugs Subject: bug#25572: Signatures on Emacs windows .zip files Date: Sun, 29 Jan 2017 20:36:15 +0000 Message-ID: References: <92b7e28f-8e37-21f4-ca46-0d4ca9429c4a@terraraq.uk> <83d1f5y67j.fsf@gnu.org> NNTP-Posting-Host: blaine.gmane.org Mime-Version: 1.0 Content-Type: text/plain; charset=windows-1252 Content-Transfer-Encoding: 8bit X-Trace: blaine.gmane.org 1485737665 1520 195.159.176.226 (30 Jan 2017 00:54:25 GMT) X-Complaints-To: usenet@blaine.gmane.org NNTP-Posting-Date: Mon, 30 Jan 2017 00:54:25 +0000 (UTC) User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Thunderbird/45.6.0 Cc: 25572@debbugs.gnu.org To: Eli Zaretskii Original-X-From: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Mon Jan 30 01:54:20 2017 Return-path: Envelope-to: geb-bug-gnu-emacs@m.gmane.org Original-Received: from lists.gnu.org ([208.118.235.17]) by blaine.gmane.org with esmtp (Exim 4.84_2) (envelope-from ) id 1cY0Ed-0008RK-Ph for geb-bug-gnu-emacs@m.gmane.org; Mon, 30 Jan 2017 01:54:19 +0100 Original-Received: from localhost ([::1]:57400 helo=lists.gnu.org) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1cY0Ee-0002dn-7t for geb-bug-gnu-emacs@m.gmane.org; Sun, 29 Jan 2017 19:54:20 -0500 Original-Received: from eggs.gnu.org ([2001:4830:134:3::10]:52811) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1cY0ER-0002dN-5p for bug-gnu-emacs@gnu.org; Sun, 29 Jan 2017 19:54:08 -0500 Original-Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1cY0EM-0003Ie-Og for bug-gnu-emacs@gnu.org; Sun, 29 Jan 2017 19:54:07 -0500 Original-Received: from debbugs.gnu.org ([208.118.235.43]:52346) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1cY0EM-0003IW-LR for bug-gnu-emacs@gnu.org; Sun, 29 Jan 2017 19:54:02 -0500 Original-Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1cY0EM-0007iX-4f for bug-gnu-emacs@gnu.org; Sun, 29 Jan 2017 19:54:02 -0500 X-Loop: help-debbugs@gnu.org Resent-From: Richard Kettlewell Original-Sender: "Debbugs-submit" Resent-CC: bug-gnu-emacs@gnu.org Resent-Date: Mon, 30 Jan 2017 00:54:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 25572 X-GNU-PR-Package: emacs X-GNU-PR-Keywords: Original-Received: via spool by 25572-submit@debbugs.gnu.org id=B25572.148573759329603 (code B ref 25572); Mon, 30 Jan 2017 00:54:02 +0000 Original-Received: (at 25572) by debbugs.gnu.org; 30 Jan 2017 00:53:13 +0000 Original-Received: from localhost ([127.0.0.1]:50543 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1cY0DY-0007hN-UN for submit@debbugs.gnu.org; Sun, 29 Jan 2017 19:53:13 -0500 Original-Received: from mantic.terraraq.uk ([46.235.226.39]:46080) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1cXwCw-0006y6-PL for 25572@debbugs.gnu.org; Sun, 29 Jan 2017 15:36:19 -0500 Original-Received: from cpc91220-cmbg18-2-0-cust198.5-4.cable.virginm.net ([81.104.142.199] helo=araminta.anjou.terraraq.org.uk) by mantic.terraraq.uk with esmtpsa (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.84_2) (envelope-from ) id 1cXwCw-0005gh-8m; Sun, 29 Jan 2017 20:36:18 +0000 Original-Received: from tsais.anjou.terraraq.org.uk ([2001:470:1f09:11ed::42]) by araminta.anjou.terraraq.org.uk with esmtpsa (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.84_2) (envelope-from ) id 1cXwCv-0001IR-Fc; Sun, 29 Jan 2017 20:36:17 +0000 In-Reply-To: <83d1f5y67j.fsf@gnu.org> X-Mailman-Approved-At: Sun, 29 Jan 2017 19:53:12 -0500 X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-detected-operating-system: by eggs.gnu.org: GNU/Linux 2.2.x-3.x [generic] X-Received-From: 208.118.235.43 X-BeenThere: bug-gnu-emacs@gnu.org List-Id: "Bug reports for GNU Emacs, the Swiss army knife of text editors" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: bug-gnu-emacs-bounces+geb-bug-gnu-emacs=m.gmane.org@gnu.org Original-Sender: "bug-gnu-emacs" Xref: news.gmane.org gmane.emacs.bugs:128778 Archived-At: On 2017-01-29 20:14, Eli Zaretskii wrote: >> According to https://www.gnu.org/software/emacs/download.html: >> >> Since the 24.5 release, tarballs are signed with the GPG key from >> Nicolas Petton 7C207910, fingerprint 28D3 BED8 51FD F3AB 57FE >> F93C 2335 87A4 7C20 7910, which can be found in the GNU keyring. >> >> However the windows .zip files on http://ftp.gnu.org/gnu/emacs are >> signed with some other key: >> >> $ gpg2 --verify emacs-25.1-2-x86_64-w64-mingw32.zip.sig >> gpg: Signature made 11/29/16 19:54:09 GMT Standard Time using DSA key ID >> 60C3B396 >> gpg: Good signature from "Phillip Lord " >> gpg: aka "Phillip Lord " >> gpg: aka "Phillip Lord " >> gpg: aka "Phillip Lord " >> gpg: WARNING: This key is not certified with a trusted signature! >> gpg: There is no indication that the signature belongs to the >> owner. >> Primary key fingerprint: 8352 2404 7598 ECBC 61A1 DA34 5FE9 658D 60C3 B396 > > That's because the zip files with Windows binaries were produced by > Phillip. Thankyou for replying. The point is: how do I verify that I have a legitimate download of the GNU Emacs Windows binaries? I have an informal trust path to 28D3BED851FDF3AB57FEF93C233587A47C207910 because https://www.gnu.org mentions it. No such statement exists about 835224047598ECBC61A1DA345FE9658D60C3B396. > Why is that a bug? The web page told me to send comments to bug-gnu-emacs@gnu.org, and so here we are. Is there some more appropriate reporting channel? ttfn/rjk