Author

Topic: Electrum Authentication through GPG keychain (Read 168 times)

newbie
Activity: 4
Merit: 8
August 09, 2020, 10:34:05 AM
#8
...I see...now I set the option "Ownertrust" from "full" to "ultimate" and now it says "Absolute trusted signature"
but I got your important point that actually its just trustworthy  if I get the signature from ThomasV personally
Thanks a lot
newbie
Activity: 4
Merit: 8
...I set it to trusted manually - I understand the point you are mentioning - about trust - at one point in the chain you need to trust...which is probably not justified
so if I got you right - the authentication process is ok so far - just wonder why it says not trustworthy even I set it to "trusted" before
legendary
Activity: 2758
Merit: 6830
but in the end GPG says "Untrusted signature - This signature is not to be trusted"
This just means that you haven't manually set the key you imported as "trusted". The signature matches, which is the important part, but... what does that mean? What if you used a random/fake key and it matched? The software doesn't know if the key is really from ThomasV, so that's why they give this warning.

I think you can set it as trusted by right clicking it and choosing whatever option is there (depends on the software you are using).
newbie
Activity: 4
Merit: 8
Thanks guys so far - I took everything (ThomasV signature, the download itself and the signature of the download) directly from electrum.org but in the end GPG says "Untrusted signature - This signature is not to be trusted"
I must say - I am really not too familiar with this computer stuff - any ideas?  Roll Eyes
Thank you
legendary
Activity: 2268
Merit: 18771
Electrum's public key
Electrum doesn't have a public key. ThomasV, as the lead developer of Electrum, signs the releases using his public key.

but when I am entering this in the PGP's "lookup for keys" search it doesnt find it.
What directory are you searching in?

I can also verify the key you have shared is correct, but as above, you shouldn't trust random people on the internet. You can also find his key at the following places:

http://keys.gnupg.net/pks/lookup?search=0x2bd5824b7f9470e6&fingerprint=on&op=vindex
https://pgp.key-server.io/pks/lookup?search=0x2bd5824b7f9470e6&fingerprint=on&op=vindex
hero member
Activity: 1722
Merit: 801
How to Safely Download and Verify Electrum. You can read it and practice. In that thread, there are some links to official sources of Electrum wallet but as Try Ninja advised, don't trust him, trust me nor DireWolf. Check and verify.
legendary
Activity: 2758
Merit: 6830
You can get his key from the Electrum's github repo: https://github.com/spesmilo/electrum/blob/master/pubkeys/ThomasV.asc

(Double check this is the real repo, do not trust me. Smiley)
newbie
Activity: 4
Merit: 8
hi, can anybody help me to get the right Electrum's public key I need to enter in the GPG keychain - so that I can verify my electrums download in a second step. What I found so far is from 2017 - its the Thomas Voegtlins public key "0x2bd5824b7f9470e6" - but when I am entering this in the PGP's "lookup for keys" search it doesnt find it.
Thanks a lot
Valentin
Jump to: