Date: Fri, 30 Dec 2016 17:56:15 +1100 From: Felix Friedlander <felixphew0@gmail.com> To: freebsd-questions@freebsd.org Subject: Fwd: Signatures Message-ID: <6EF4ACC2-DD83-4970-9346-12600DFF2362@gmail.com> References: <995C6DE9-DAAF-47DD-BFF4-9FAC1A917BAA@gmail.com>
next in thread | previous in thread | raw e-mail | index | archive | help
[-- Attachment #1 --] Re-including the list. > Begin forwarded message: > > From: Felix Friedlander <felixphew0@gmail.com> > Subject: Re: Signatures > Date: 30 December 2016 at 5:55:06 pm AEDT > To: Specter <neurospecter@protonmail.ch> > > >> On 30 Dec 2016, at 5:46 pm, Specter <neurospecter@protonmail.ch> wrote: >> >> Felix, >> >> Thank you for your response all though that comes as quite a surprise. I've had the impression that BSD is for the security conscious yet you do not sign your ISO's. I'm a Linux user at the moment and just about every Linux developer out there signs their ISO's. I just can't imagine that's the case. >> >> Are you absolutely sure? I have actually found that key before but as you said, that is not a signing key for the ISO's which is what I need. I refuse to use anything that has not been properly signed. I am very security conscious. >> >> Thanks, >> Spectral >> >> >>> -------- Original Message -------- >>> Subject: Re: Signatures >>> Local Time: 29 December 2016 10:40 PM >>> UTC Time: 30 December 2016 06:40 >>> From: felixphew0@gmail.com >>> To: Specter <neurospecter@protonmail.ch> >>> freebsd-questions@freebsd.org <freebsd-questions@freebsd.org> >>> >>>> On 30 Dec 2016, at 5:27 pm, Specter via freebsd-questions <freebsd-questions@freebsd.org> wrote: >>>> >>>> Hello, I was wondering where you've posted your public signing keys? I have not been able to find them anywhere. And where can I find the signature files for your ISO's? >>>> >>>> Thanks, >>>> Spectral >>> >>> To the best of my knowledge, FreeBSD ISO images are not signed. You can verify their integrity (to a degree) using the checksums (example: http://ftp.freebsd.org/pub/FreeBSD/releases/amd64/amd64/ISO-IMAGES/11.0/CHECKSUM.SHA256-FreeBSD-11.0-RELEASE-amd64 ). >>> >>> The only “official” PGP key for the project (as far as I’m aware) belongs to the security officer, and is used for signing security advisories. You can find the key at https://www.freebsd.org/security/so_public_key.asc and the advisories at https://www.freebsd.org/security/advisories.html. >>> >>> Feel free to correct me, anyone, if this is out-of-date or incorrect. >>> >>> -- >>> Felix Friedlander <felixphew0@gmail.com> >>> >> > > Hi, > > As I suspected my information was quite out-of-date. > > Signed checksums for each release can be found on the website, near the release announcements, notes, and errata. For example: https://www.freebsd.org/releases/11.0R/signatures.html contains all the relevant signatures for FreeBSD 11.0-RELEASE. > > I’m not entirely sure which key these are signed with, but it should be one of the keys found at https://www.freebsd.org/doc/en/articles/pgpkeys/ (downloadable as one file at https://www.freebsd.org/doc/pgpkeyring.txt if you need to automate this or something). > > -- > Felix Friedlander <felixphew0@gmail.com> > -- Felix Friedlander <felixphew0@gmail.com> [-- Attachment #2 --] 0 *H 010 + 0 *H _0u0]M}gd}/'г30 *H 0u10 UIL10U StartCom Ltd.1)0'U StartCom Certification Authority1#0!UStartCom Class 1 Client CA0 161204063157Z 200304063157Z0D10Ufelixphew0@gmail.com1#0! *H felixphew0@gmail.com00*H=+ # ml1OqQQM]VN~RĿP 534XMc#''^6v9 *J rjWfe7^NY* *F0N>.M(L۾rCJaC2'Xף00U0U%0++0 U0 0US 7X'ܨJ$(, 0U#0$l9aIF+('Hmh0o+c0a0$+0http://ocsp.startssl.com09+0-http://aia.startssl.com/certs/sca.client1.crt08U10/0-+)'http://crl.startssl.com/sca-client1.crl0U0felixphew0@gmail.com0#U0http://www.startssl.com/0GU @0>0<+70-0++https://www.startssl.com/policy0 *H $bdṁ̃CNBUneSA 2HCj'D)3 6t JcˌH:zRB 7$̊B.QiGf')nbCH=بdg@s6,HܫCŁഉ9hEJho{O0`>[˱Lf.Ѷw[zlv};dRkaQ?IƏ3m,%((Hyl&#Fq00ʠk} Q Y0 *H 0}10 UIL10U StartCom Ltd.1+0)U"Secure Digital Certificate Signing1)0'U StartCom Certification Authority0 151216010005Z 301216010005Z0u10 UIL10U StartCom Ltd.1)0'U StartCom Certification Authority1#0!UStartCom Class 1 Client CA0"0 *H 0 }â}[[_u$Wy5 |̔ vnqY)\aL$dYG|B"QǤĩVD#'F k9O_]*ςz_kU.u3r #:C<ogT)K Xah8v[\KqdlO)3+u7J5";[vfL/"2ϩJ#4ד[U TB,a˖a7H< =q d0`0U0U%0++0U0 02U+0)0'%#!http://crl.startssl.com/sfsca.crl0f+Z0X0$+0http://ocsp.startssl.com00+0$http://aia.startssl.com/certs/ca.crt0U$l9aIF+('Hmh0U#0N@[i04hCA0?U 80604U 0,0*+http://www.startssl.com/policy0 *H [#'#4pnRۡЗN⛭`]K"#H*߷Թψ;UA8Ҟeg{ozmYE60A)wXRK6c^-Al^k[':G=;oLv{$B5;8b,ZP4{o[-j m)[땭[4 s.c|ҴvYLJ<|ӯgu0jD2 @hl+:j\ze_ևa@HyMHINxpK?% 㤺RC:=?^&7m´)A2;E~VB1$EvcKj؝(OoپU`"$a;ҡj0$&<$ۊ+/xjzb,7}W*1ܺtDv#8K %^P>/i?)yRuQg^z`~sP91000u10 UIL10U StartCom Ltd.1)0'U StartCom Certification Authority1#0!UStartCom Class 1 Client CAM}gd}/'г30 + 0 *H 1 *H 0 *H 1 161230065616Z0# *H 1ю#na|`q'0 +7100u10 UIL10U StartCom Ltd.1)0'U StartCom Certification Authority1#0!UStartCom Class 1 Client CAM}gd}/'г30*H 10u10 UIL10U StartCom Ltd.1)0'U StartCom Certification Authority1#0!UStartCom Class 1 Client CAM}gd}/'г30 *H=0B H C. lrI%)):qoefXx,ABf{s#JBWCSM~O6o/saoQM~*S'
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?6EF4ACC2-DD83-4970-9346-12600DFF2362>
