GPG Keychain: GPG Tools Public Signature in Website Footer does not match the Public Signature of the downloaded file

 Cardamom Jones's Avatar

Cardamom Jones

27 Dec, 2020 02:46 PM

Hi,

I downloaded GPG suite from the homepage link (https://releases.gpgtools.org/GPG_Suite-2020.2.dmg) and the corresponding signature file (https://releases.gpgtools.org/GPG_Suite-2020.2.dmg.sig).

When I try to verify the signature of the file in terminal, the public key that it says that it is signed with is 8C31E5A17DD5D932B448FE1DE8A66448OD9E43F5, however on the home page in the footer it says the GPGTools Public Key is 85E3 8F69 046B 44C1 EC9F B07B 76D7 8F05 00D0 26C4.

What is causing this discrepancy and is the file safe?

I noticed the 8C31E5A17DD5D932B448FE1DE8A66448OD9E43F5 key matches the public key in the screenshot on this guide (https://gpgtools.tenderapp.com/kb/how-to/how-to-verify-the-download...), however why would there be a different public key in the footer of the website?

Thanks for any help!

  1. Support Staff 1 Posted by Steve on 31 Dec, 2020 03:32 PM

    Steve's Avatar

    Hi Cardamom Jones,

    welcome to the GPGTools support platform.

    8C31 E5A1 7DD5 D932 B448 FE1D E8A6 6448 0D9E 43F5 is the fingerprint of the subkey of key 85E3 8F69 046B 44C1 EC9F B07B 76D7 8F05 00D0 26C4.

    You can see this by searching for the second fingerprint, double clicking the key that shows and looking at the fingerprint you see in the subkey tab.

    There is a problem though with parsing the fingerprint of a subkey when using spaces in the fingerprint in the search in GPG Keychain. Clearly that should not happen.

    We have a ticket for this problem. I connected this discussion with the existing ticket. That means, should this discussion get closed, it will be re-opened as soon as the ticket is closed. That way you stay in the loop and will receive info as soon as we have news. Feel free to open a new discussion should you run into further problems or need assistance.

    All the best and happy new year 🎉
    Steve

  2. 2 Posted by Cardamom Jones on 02 Jan, 2021 03:58 PM

    Cardamom Jones 's Avatar

    Thanks Steve, really appreciate the help. That makes sense and I can see it as a subkey.

    Happy New Year!

  3. Support Staff 3 Posted by Steve on 05 Jan, 2021 11:56 PM

    Steve's Avatar

    Glad this is solved for you. I'm closing this discussion. Should you need further assistance or have questions you can re-open this discussion here or open a new one any time.

    Best,
    Steve

  4. Steve closed this discussion on 05 Jan, 2021 11:56 PM.

Comments are currently closed for this discussion. You can start a new one.

Keyboard shortcuts

Generic

? Show this help
ESC Blurs the current field

Comment Form

r Focus the comment reply box
^ + ↩ Submit the comment

You can use Command ⌘ instead of Control ^ on Mac