Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 30 Dec 2016 17:56:15 +1100
From:      Felix Friedlander <felixphew0@gmail.com>
To:        freebsd-questions@freebsd.org
Subject:   Fwd: Signatures
Message-ID:  <6EF4ACC2-DD83-4970-9346-12600DFF2362@gmail.com>
References:  <995C6DE9-DAAF-47DD-BFF4-9FAC1A917BAA@gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
Re-including the list.

> Begin forwarded message:
> 
> From: Felix Friedlander <felixphew0@gmail.com>
> Subject: Re: Signatures
> Date: 30 December 2016 at 5:55:06 pm AEDT
> To: Specter <neurospecter@protonmail.ch>
> 
> 
>> On 30 Dec 2016, at 5:46 pm, Specter <neurospecter@protonmail.ch> wrote:
>> 
>> Felix,
>> 
>> Thank you for your response all though that comes as quite a surprise. I've had the impression that BSD is for the security conscious yet you do not sign your ISO's. I'm a Linux user at the moment and just about every Linux developer out there signs their ISO's. I just can't imagine that's the case. 
>> 
>> Are you absolutely sure? I have actually found that key before but as you said, that is not a signing key for the ISO's which is what I need. I refuse to use anything that has not been properly signed. I am very security conscious.
>> 
>> Thanks,
>> Spectral
>> 
>> 
>>> -------- Original Message --------
>>> Subject: Re: Signatures
>>> Local Time: 29 December 2016 10:40 PM
>>> UTC Time: 30 December 2016 06:40
>>> From: felixphew0@gmail.com
>>> To: Specter <neurospecter@protonmail.ch>
>>> freebsd-questions@freebsd.org <freebsd-questions@freebsd.org>
>>> 
>>>> On 30 Dec 2016, at 5:27 pm, Specter via freebsd-questions <freebsd-questions@freebsd.org> wrote:
>>>> 
>>>> Hello, I was wondering where you've posted your public signing keys? I have not been able to find them anywhere. And where can I find the signature files for your ISO's?
>>>> 
>>>> Thanks,
>>>> Spectral
>>> 
>>> To the best of my knowledge, FreeBSD ISO images are not signed. You can verify their integrity (to a degree) using the checksums (example: http://ftp.freebsd.org/pub/FreeBSD/releases/amd64/amd64/ISO-IMAGES/11.0/CHECKSUM.SHA256-FreeBSD-11.0-RELEASE-amd64 ).
>>> 
>>> The only “official” PGP key for the project (as far as I’m aware) belongs to the security officer, and is used for signing security advisories. You can find the key at https://www.freebsd.org/security/so_public_key.asc and the advisories at https://www.freebsd.org/security/advisories.html.
>>> 
>>> Feel free to correct me, anyone, if this is out-of-date or incorrect.
>>> 
>>> -- 
>>> Felix Friedlander <felixphew0@gmail.com>
>>> 
>> 
> 
> Hi,
> 
> As I suspected my information was quite out-of-date.
> 
> Signed checksums for each release can be found on the website, near the release announcements, notes, and errata. For example: https://www.freebsd.org/releases/11.0R/signatures.html contains all the relevant signatures for FreeBSD 11.0-RELEASE.
> 
> I’m not entirely sure which key these are signed with, but it should be one of the keys found at https://www.freebsd.org/doc/en/articles/pgpkeys/ (downloadable as one file at https://www.freebsd.org/doc/pgpkeyring.txt if you need to automate this or something).
> 
> -- 
> Felix Friedlander <felixphew0@gmail.com>
> 

-- 
Felix Friedlander <felixphew0@gmail.com>


[-- Attachment #2 --]
0	*H
010	+0	*H

_0u0]M}g؜d}/'г30
	*H
0u10	UIL10U

StartCom Ltd.1)0'U StartCom Certification Authority1#0!UStartCom Class 1 Client CA0
161204063157Z
200304063157Z0D10Ufelixphew0@gmail.com1#0!	*H
	felixphew0@gmail.com00*H=+#ml1OqQQM]VN~RĿP
534XMc#''^6v9*J	rjWfe7^NY*  *F0N>.M(L۾rCJaC2'Xף00U0U%0++0	U00US	7X'ܨJ$(,
0U#0$l9aIF+('Hmh0o+c0a0$+0http://ocsp.startssl.com09+0-http://aia.startssl.com/certs/sca.client1.crt08U10/0-+)'http://crl.startssl.com/sca-client1.crl0U0felixphew0@gmail.com0#U0http://www.startssl.com/0GU @0>0<+70-0++https://www.startssl.com/policy0
	*H
$bdṁ̃CNBUneSA
2HCj'D)3	6t JcˌH:zRB
7$̊B.QiGf')nbCH=بdg@s6,HܫCŁ΂ഉ9hEJho{O0`>[˱Lf.Ѷw[zlv};dRkaQ?IƏ3m,%((Hyl&#Fq00ʠk}
׈Q
Y0
	*H
0}10	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1)0'U StartCom Certification Authority0
151216010005Z
301216010005Z0u10	UIL10U

StartCom Ltd.1)0'U StartCom Certification Authority1#0!UStartCom Class 1 Client CA0"0
	*H
0
}â}[[_u$Wy5	|̔
vnqY)\aL$dYG|B"QǤĩVD#'F	k9O_]*ςz_kU.u3r	#:C<ogT)K
Xah8v[\KqdlO)3+u7J5";[vfL/"2ϩJ#4ד[U TB,a˖a7H<=qd0`0U0U%0++0U002U+0)0'%#!http://crl.startssl.com/sfsca.crl0f+Z0X0$+0http://ocsp.startssl.com00+0$http://aia.startssl.com/certs/ca.crt0U$l9aIF+('Hmh0U#0N@[i04hCA0?U 80604U 0,0*+http://www.startssl.com/policy0
	*H
[#'#4pnRۡЗN⛭`]K"#H*߷Թψ;UA8Ҟeg{ozmYE60A)wXRK6c^-Al^k[':G=;oLv{$B5;8b,ZP4{o[-໢j	׏m)[땭[4	s.c|ҴvYLJ<|ӯgu0jD2
@hl+:j\ze_ևa@HyMHINxpK?%	㤺RC:=?^&7m´)A2;E~VB1$EvcKj؝(OoپU`"$a;ҡj0$&<$ۊ+/xjzb,7}W*1ܺtDv#8K
%^P>/i?)yRuQg^z`~sP91000u10	UIL10U

StartCom Ltd.1)0'U StartCom Certification Authority1#0!UStartCom Class 1 Client CAM}g؜d}/'г30	+0	*H
	1	*H
0	*H
	1
161230065616Z0#	*H
	1ю#na|`q'0	+7100u10	UIL10U

StartCom Ltd.1)0'U StartCom Certification Authority1#0!UStartCom Class 1 Client CAM}g؜d}/'г30*H
	10u10	UIL10U

StartCom Ltd.1)0'U StartCom Certification Authority1#0!UStartCom Class 1 Client CAM}g؜d}/'г30	*H=0BH C.	lrI%)):qoefXx,ABf{s#JBWCSM~O6o/saoQM~*S'

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?6EF4ACC2-DD83-4970-9346-12600DFF2362>