<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://thehidden-wiki.org/wiki/index.php?action=history&amp;feed=atom&amp;title=Verifying_PGP_signatures</id>
	<title>Verifying PGP signatures - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://thehidden-wiki.org/wiki/index.php?action=history&amp;feed=atom&amp;title=Verifying_PGP_signatures"/>
	<link rel="alternate" type="text/html" href="https://thehidden-wiki.org/wiki/index.php?title=Verifying_PGP_signatures&amp;action=history"/>
	<updated>2026-08-29T18:54:22Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.46.0</generator>
	<entry>
		<id>https://thehidden-wiki.org/wiki/index.php?title=Verifying_PGP_signatures&amp;diff=6&amp;oldid=prev</id>
		<title>Admin: Created page with &quot;== Before you download Tor == :&#039;&#039;For more info&#039;&#039;, see the guide on the official Tor website: https://www.torproject.org/docs/verifying-signatures.html.en  &lt;div style=&quot;border:...&quot;</title>
		<link rel="alternate" type="text/html" href="https://thehidden-wiki.org/wiki/index.php?title=Verifying_PGP_signatures&amp;diff=6&amp;oldid=prev"/>
		<updated>2019-10-31T21:07:26Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;== Before you download Tor == :&amp;#039;&amp;#039;For more info&amp;#039;&amp;#039;, see the guide on the official Tor website: https://www.torproject.org/docs/verifying-signatures.html.en  &amp;lt;div style=&amp;quot;border:...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;== Before you download Tor ==&lt;br /&gt;
:&amp;#039;&amp;#039;For more info&amp;#039;&amp;#039;, see the guide on the official Tor website: https://www.torproject.org/docs/verifying-signatures.html.en&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;border: 1px solid #bce; background: #f8fcff; padding: 8px; width: 60%; margin-left: 5%&amp;quot;&amp;gt;&lt;br /&gt;
To follow this guide, one of these three programs should be used:	&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;GNU Privacy Assistant&amp;#039;&amp;#039;&amp;#039;&amp;amp;mdash;comes with the GPG binary package for almost every platform. It is usually found in the same directory as the &amp;lt;code&amp;gt;gpg&amp;lt;/code&amp;gt; command.*&amp;#039;&amp;#039;&amp;#039;Kleopatra&amp;#039;&amp;#039;&amp;#039;&amp;amp;mdash;comes with GnuPG4win (http://gpg4win.org). It has a more pleasant interface, but is more prone to crashing. It should be available in the &amp;#039;&amp;#039;&amp;#039;Quick Start&amp;#039;&amp;#039;&amp;#039; menu after the program is installed.*&amp;#039;&amp;#039;&amp;#039;gpg via command-line interface&amp;#039;&amp;#039;&amp;#039;&amp;amp;mdash;always available, but slightly more cumbersome and error-prone. On most systems, go to a command prompt and type the &amp;lt;code&amp;gt;gpg&amp;lt;/code&amp;gt; command. On Windows, the command is placed in the &amp;lt;code&amp;gt;%SystemDrive%\Progra~1\GNU\GnuPG\pub&amp;lt;/code&amp;gt; directory after it is installed.	&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most Tor binary executable packages are &amp;#039;&amp;#039;&amp;#039;signed&amp;#039;&amp;#039;&amp;#039; by Erinn Clark and can be verified using her PGP &amp;#039;&amp;#039;&amp;#039;public key&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
#&amp;#039;&amp;#039;&amp;#039;Obtain the PGP public key&amp;#039;&amp;#039;&amp;#039;&amp;lt;br /&amp;gt;The public key can be obtained through one of several ways:&amp;lt;br /&amp;gt;&lt;br /&gt;
#*&amp;#039;&amp;#039;&amp;#039;Retrieving it from a keyserver&amp;#039;&amp;#039;&amp;#039;&amp;lt;br /&amp;gt;It is easiest just to use &amp;#039;&amp;#039;&amp;#039;hkp://keys.gnupg.net&amp;#039;&amp;#039;&amp;#039; which is the default keyserver. The fingerprint of Erinn&amp;amp;rsquo;s public key is &amp;#039;&amp;#039;&amp;#039;8738 A680 B84B 3031 A630  F2DB 416F 0610 63FE E659&amp;#039;&amp;#039;&amp;#039;. Her key ID is &amp;#039;&amp;#039;&amp;#039;0x&amp;#039;&amp;#039;&amp;#039; followed by the last 8 characters of the fingerprint &amp;amp;ndash; namely, &amp;#039;&amp;#039;&amp;#039;0x63FEE659&amp;#039;&amp;#039;&amp;#039;.	&lt;br /&gt;
#**GNU Privacy Assistant:&lt;br /&gt;
#**#In the &amp;#039;&amp;#039;&amp;#039;Key Manager&amp;#039;&amp;#039;&amp;#039;, click the &amp;#039;&amp;#039;&amp;#039;Preferences&amp;#039;&amp;#039;&amp;#039; button (or select it from the Edit menu). The address &amp;lt;code&amp;gt;hkp://keys.gnupg.net&amp;lt;/code&amp;gt; should be filled in the &amp;#039;&amp;#039;&amp;#039;Default keyserver&amp;#039;&amp;#039;&amp;#039; field. Click OK.	&lt;br /&gt;
#**#Click the &amp;#039;&amp;#039;&amp;#039;Server&amp;#039;&amp;#039;&amp;#039; menu and select &amp;#039;&amp;#039;&amp;#039;Retrieve keys&amp;#039;&amp;#039;&amp;#039;. A small dialog box should pop up. Input &amp;lt;code&amp;gt;0x63FEE659&amp;lt;/code&amp;gt; for &amp;#039;&amp;#039;&amp;#039;Key ID&amp;#039;&amp;#039;&amp;#039;. Click OK.&lt;br /&gt;
#**#If the key is found, it will be automatically imported to your keyring.&lt;br /&gt;
#**Kleopatra:&lt;br /&gt;
#**#Click the &amp;#039;&amp;#039;&amp;#039;Settings&amp;#039;&amp;#039;&amp;#039; menu and select &amp;#039;&amp;#039;&amp;#039;Configure Kleopatra&amp;#039;&amp;#039;&amp;#039;. When the Configure window comes up, go to the &amp;#039;&amp;#039;&amp;#039;Directory Services&amp;#039;&amp;#039;&amp;#039; section. You should see &amp;amp;ldquo;hkp://keys.gnupg.net&amp;amp;rdquo; listed with the scheme &amp;amp;ldquo;hkp&amp;amp;rdquo; and the &amp;amp;ldquo;OpenGPG&amp;amp;rdquo; box checked. Click OK.&lt;br /&gt;
#**#With the main window in focus, click the &amp;#039;&amp;#039;&amp;#039;Lookup Certificates on Server&amp;#039;&amp;#039;&amp;#039; button (with a picture of binoculars), or select it from the File menu. The Certificate Lookup window should pop up.&lt;br /&gt;
#**#Input &amp;lt;code&amp;gt;0x63FEE659&amp;lt;/code&amp;gt; in the &amp;#039;&amp;#039;&amp;#039;Find&amp;#039;&amp;#039;&amp;#039; field and click &amp;#039;&amp;#039;&amp;#039;Search&amp;#039;&amp;#039;&amp;#039;.	&lt;br /&gt;
#**#If the key is found, select it and click &amp;#039;&amp;#039;&amp;#039;Import&amp;#039;&amp;#039;&amp;#039; to import it to your keyring.&lt;br /&gt;
#**Command line:&amp;lt;br /&amp;gt;Type &amp;lt;code&amp;gt;gpg --keyserver hkp://keys.gnupg.net --recv-keys 0x63fee659&amp;lt;/code&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;	&lt;br /&gt;
#*&amp;#039;&amp;#039;&amp;#039;Obtaining Erinn&amp;#039;s key in person&amp;#039;&amp;#039;&amp;#039;&amp;lt;br /&amp;gt;This is considered the most secure, although she is an individual and cannot always give out her key to the thousands of people who use Tor regularly.&amp;lt;br /&amp;gt;Since Erinn is a Debian developer, you might be able to meet her at a free software, open source software, or Linux IT conference. Hopefully there will be a sign somewhere displaying a hardcopy of her key. In that case, you can transcribe it to a keyfile (see below). If not, then maybe you can agree on another way to transfer it (such as a [http://www.gnupg.org/documentation/howtos.en.html key-signing party]).&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;	&lt;br /&gt;
#*&amp;#039;&amp;#039;&amp;#039;Importing the key from a keyfile&amp;#039;&amp;#039;&amp;#039;&amp;lt;br /&amp;gt;Generally, the keyfile is obtained either in person (see above), by asking someone else to export it from a keyring (&amp;lt;code&amp;gt;gpg --export -a 0x63fee659 &amp;gt; erinn_clark.asc&amp;lt;/code&amp;gt;), through a dedicated URL (for example, http://www.cacert.org/certs/cacert.asc) or by copying-and-pasting from a webpage (for example, http://dev.mysql.com/doc/refman/5.0/en/checking-gpg-signature.html).&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;There is a keyfile at http://deb.torproject.org/archive-key.asc which is used to verify the [http://deb.torproject.org/torproject.org/dists/ checksums] of the [http://deb.torproject.org/torproject.org/pool/main/ Debian and Ubuntu GNU/Linux versions of Tor and Vidalia]. For other operating systems (such as Windows or Mac OS), the key must be obtained using another method.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Once the user has a keyfile, the key may be imported in the following manner:&lt;br /&gt;
#**GNU Privacy Assistant:&lt;br /&gt;
#**#In the &amp;#039;&amp;#039;&amp;#039;Key Manager&amp;#039;&amp;#039;&amp;#039;, click the &amp;#039;&amp;#039;&amp;#039;Import&amp;#039;&amp;#039;&amp;#039; button. A file selector should pop up.&lt;br /&gt;
#**#Locate the file then click &amp;#039;&amp;#039;&amp;#039;Open&amp;#039;&amp;#039;&amp;#039;. The key should be automatically imported.&lt;br /&gt;
#**Kleopatra:&lt;br /&gt;
#***Drag-and-drop the file into the main window. A context menu pops up. Choose &amp;#039;&amp;#039;&amp;#039;Import Certificates&amp;#039;&amp;#039;&amp;#039;, or&lt;br /&gt;
#***Click the &amp;#039;&amp;#039;&amp;#039;Import Certificates&amp;#039;&amp;#039;&amp;#039; button, or select it from the File menu. A file selector should pop up.&amp;lt;br /&amp;gt;Locate the file then click &amp;#039;&amp;#039;&amp;#039;Open&amp;#039;&amp;#039;&amp;#039;. The key should be automatically imported.&lt;br /&gt;
#**Command line:&amp;lt;br /&amp;gt;Type &amp;lt;code&amp;gt;gpg --import &amp;lt;/code&amp;gt; followed by the name of the signature file and press &amp;lt;ENTER&amp;gt;. A modern console emulator will allow you to drag-and-drop the file instead of typing out its name.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
#&amp;#039;&amp;#039;&amp;#039;Double-check the key&amp;#039;s fingerprint&amp;#039;&amp;#039;&amp;#039;&amp;lt;br /&amp;gt;You will do this by physically reading it.&lt;br /&gt;
#*GNU Privacy Assistant:&lt;br /&gt;
#*#In the &amp;#039;&amp;#039;&amp;#039;Key Manager&amp;#039;&amp;#039;&amp;#039;, click the &amp;#039;&amp;#039;&amp;#039;Key ID&amp;#039;&amp;#039;&amp;#039; column to sort the keys numerically by ID.&lt;br /&gt;
#*#Scroll until you reach an item with ID number &amp;#039;&amp;#039;&amp;#039;63FEE659&amp;#039;&amp;#039;&amp;#039;. It should have the name &amp;#039;&amp;#039;&amp;#039;Erinn Clark &amp;lt;erinn@torproject.org&amp;gt;&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
#*#Select that item.&lt;br /&gt;
#*#In the &amp;#039;&amp;#039;&amp;#039;Details&amp;#039;&amp;#039;&amp;#039; tab below, you should see a row that says &amp;#039;&amp;#039;&amp;#039;Key ID: 63FEE659&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
#*#Check that the row below it says: &amp;#039;&amp;#039;&amp;#039;Fingerprint: 8738 A680 B84B 3031 A630  F2DB 416F 0610 63FE E659&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
#*Kleopatra:&lt;br /&gt;
#*#After importing the key, it should be listed in a new tab named &amp;#039;&amp;#039;&amp;#039;Imported Certificates&amp;#039;&amp;#039;&amp;#039;. If not, then open a new tab with the &amp;amp;ldquo;All Certificates&amp;amp;rdquo; option.&lt;br /&gt;
#*#Look for an item with Key-ID &amp;#039;&amp;#039;&amp;#039;63FEE659&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
#*#Get the key&amp;#039;s properties by either:&lt;br /&gt;
#*#*Double-clicking the item,&lt;br /&gt;
#*#*Right clicking the item and choosing &amp;#039;&amp;#039;&amp;#039;Certificate Details&amp;#039;&amp;#039;&amp;#039;, or&lt;br /&gt;
#*#*Selecting the item, going to the &amp;#039;&amp;#039;&amp;#039;View&amp;#039;&amp;#039;&amp;#039; menu, then selecting &amp;#039;&amp;#039;&amp;#039;Certificate Details&amp;#039;&amp;#039;&amp;#039;&lt;br /&gt;
#*Command line:&amp;lt;br /&amp;gt;&lt;br /&gt;
#*#Type &amp;lt;code&amp;gt;gpg --fingerprint 0x63fee659&amp;lt;/code&amp;gt;&lt;br /&gt;
#*#Check that the program prints the following:&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;pre style=&amp;quot;width: 60em&amp;quot;&amp;gt;&lt;br /&gt;
pub   2048R/63FEE659 2003-10-16&lt;br /&gt;
      Key fingerprint = 8738 A680 B84B 3031 A630  F2DB 416F 0610 63FE E659&lt;br /&gt;
uid                  Erinn Clark &amp;lt;erinn@torproject.org&amp;gt;&lt;br /&gt;
uid                  Erinn Clark &amp;lt;erinn@debian.org&amp;gt;&lt;br /&gt;
uid                  Erinn Clark &amp;lt;erinn@double-helix.org&amp;gt;&lt;br /&gt;
sub   2048R/EB399FD7 2003-10-16&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Admin</name></author>
	</entry>
</feed>