VERIFYING
armory_0.95.1_amd64.deb ?
Now that I got Lubuntu installed in another 64 system, I downloaded the package from
https://btcarmory.com/0.95.1-release/Don't see any information on verification at the site.
What release signature ?
What release signing key?
EDIT: Ok sorry, just saw the information at the site. Will try and report here my process of verification.
STEPS TO VERIFY I've done:
1) Import Armory Signing Key:
gpg --recv-keys --keyserver keyserver.ubuntu.com 4922589A
gpg: key 8C5211764922589A: public key "goatpig (Offline signing key for Armory releases) <
[email protected]>" imported
gpg: no ultimately trusted keys found
gpg: Total number processed: 1
gpg: imported: 1
2) Download release signing key from:
https://btcarmory.com/0.95.1-release/3) shasum -c sha256sum.asc armory_0.95.1_amd64.deb
armory_0.95.1_amd64.deb: OK
<-- OK shasum: armory_0.95.1_osx.tar.gz:
armory_0.95.1_osx.tar.gz: FAILED open or read
shasum: armory_0.95.1_win64.exe: No such file or directory
armory_0.95.1_win64.exe: FAILED open or read
shasum: WARNING: 20 lines are improperly formatted
shasum: WARNING: 2 listed files could not be read
shasum: armory_0.95.1_amd64.deb: no properly formatted SHA1 checksum lines found
3.1)Compare the hash of the sha256sum.asc file with the one in the application package:
a) Inside the sha256sum.asc file:
4d692a60afc114f4ccb230d11006c69af12ee37a0b7964b03caff90b6619b75c armory_0.95.1_amd64.deb
b) sha256sum armory_0.95.1_amd64.deb
4d692a60afc114f4ccb230d11006c69af12ee37a0b7964b03caff90b6619b75c armory_0.95.1_amd64.deb <---inside the application package
They coincide so
<-- OK 4) gpg --verify
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
4d692a60afc114f4ccb230d11006c69af12ee37a0b7964b03caff90b6619b75c armory_0.95.1_amd64.deb
9ec3803b914660c5fbecfd5b2d6e907f64d16f920cd648678137d307399beb8d armory_0.95.1_osx.tar.gz
ccb495aa3a695e43ac04b4741dd8f8463d5349192a0f5db895dbd2e834e5844a armory_0.95.1_win64.exe
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIcBAEBCAAGBQJYGjjiAAoJEIxSEXZJIliaQ2EP/RwLphwj0z0o00VP/PGHzKYK
UmTHibof3ZavFF1orAdgWDayHoQCsZBcPy8fQcGWZ3zomhAqCC1lN496SHkkWQWH
TAYvMOsRlvMaaNIcoJ+jxyJzjmWd5+FjOEd/Uy9Au6DQFCqIEHTbjth/hyyUouaM
IxqudEiGAye2V5sIP8XWIWz6l8vq9OPKd4x3/F3NvlBY6jpAc81VxGFnfAZgIpW6
+in302WwIg61zG5AeVfju6BKJCREMvJvSvrdcrnK0UZDFm2jnl0IU1Q8omJFZXpG
EL06QBgO0+4aJ0rOu/RIIBzXJQgfj9Eul3ih0M6KbrImIAU3DlDKV3RTaNG9evCX
H5TtTKgux8Yuyljks5qu2WB7Cj8LtjbzPHMf4QT2SfavFpejJJFEAWyx2GdLTd5y
jZ95dwbPby59gyfwK3FNurgRduW+hjTGjTtZAk7CopkbrbLW4NzdjtHfKKzHmqid
yTI2PMCCjOLnAvTxEGKngmACQSvzDT9NN9ImWhf/E0IRKE7JtPPAp4U8xdC0NZDk
yIUP5A4D8d7FDpv8arK8v5PV4WyiCHLjyPRmt5kOc9AAUVr/7oPZO0FI4+VyY24X
ooOtuVmt66hTPyymmd0QUeulgl0PVqsJoyENjvx8H1Q8Wdo2rHseg06r2Q174Ckr
STBuW7eIR89uaLEsgjzC
=NJYO
-----END PGP SIGNATURE-----
gpg: Signature made mié 02 nov 2016 20:05:06 CET
gpg: using RSA key 8C5211764922589A
gpg:
Good signature from "goatpig (Offline signing key for Armory releases) <
[email protected]>" [unknown]
<-- OKgpg: WARNING: This key is not certified with a trusted signature!
gpg: There is no indication that the signature belongs to the owner.
Primary key fingerprint: 745D 707F BA53 968B DF63 AA8D 8C52 1176 4922 589A