<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://thehidden-wiki.org/wiki/index.php?action=history&amp;feed=atom&amp;title=Verifying_PGP_signatures</id>
	<title>Verifying PGP signatures - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://thehidden-wiki.org/wiki/index.php?action=history&amp;feed=atom&amp;title=Verifying_PGP_signatures"/>
	<link rel="alternate" type="text/html" href="https://thehidden-wiki.org/wiki/index.php?title=Verifying_PGP_signatures&amp;action=history"/>
	<updated>2026-04-04T06:59:07Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.33.1</generator>
	<entry>
		<id>https://thehidden-wiki.org/wiki/index.php?title=Verifying_PGP_signatures&amp;diff=6&amp;oldid=prev</id>
		<title>Admin: Created page with &quot;== Before you download Tor == :''For more info'', see the guide on the official Tor website: https://www.torproject.org/docs/verifying-signatures.html.en  &lt;div style=&quot;border:...&quot;</title>
		<link rel="alternate" type="text/html" href="https://thehidden-wiki.org/wiki/index.php?title=Verifying_PGP_signatures&amp;diff=6&amp;oldid=prev"/>
		<updated>2019-10-31T21:07:26Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;== Before you download Tor == :&amp;#039;&amp;#039;For more info&amp;#039;&amp;#039;, see the guide on the official Tor website: https://www.torproject.org/docs/verifying-signatures.html.en  &amp;lt;div style=&amp;quot;border:...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;== Before you download Tor ==&lt;br /&gt;
:''For more info'', see the guide on the official Tor website: https://www.torproject.org/docs/verifying-signatures.html.en&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;border: 1px solid #bce; background: #f8fcff; padding: 8px; width: 60%; margin-left: 5%&amp;quot;&amp;gt;&lt;br /&gt;
To follow this guide, one of these three programs should be used:	&lt;br /&gt;
*'''GNU Privacy Assistant'''&amp;amp;mdash;comes with the GPG binary package for almost every platform. It is usually found in the same directory as the &amp;lt;code&amp;gt;gpg&amp;lt;/code&amp;gt; command.*'''Kleopatra'''&amp;amp;mdash;comes with GnuPG4win (http://gpg4win.org). It has a more pleasant interface, but is more prone to crashing. It should be available in the '''Quick Start''' menu after the program is installed.*'''gpg via command-line interface'''&amp;amp;mdash;always available, but slightly more cumbersome and error-prone. On most systems, go to a command prompt and type the &amp;lt;code&amp;gt;gpg&amp;lt;/code&amp;gt; command. On Windows, the command is placed in the &amp;lt;code&amp;gt;%SystemDrive%\Progra~1\GNU\GnuPG\pub&amp;lt;/code&amp;gt; directory after it is installed.	&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Most Tor binary executable packages are '''signed''' by Erinn Clark and can be verified using her PGP '''public key'''.&lt;br /&gt;
&lt;br /&gt;
#'''Obtain the PGP public key'''&amp;lt;br /&amp;gt;The public key can be obtained through one of several ways:&amp;lt;br /&amp;gt;&lt;br /&gt;
#*'''Retrieving it from a keyserver'''&amp;lt;br /&amp;gt;It is easiest just to use '''hkp://keys.gnupg.net''' which is the default keyserver. The fingerprint of Erinn&amp;amp;rsquo;s public key is '''8738 A680 B84B 3031 A630  F2DB 416F 0610 63FE E659'''. Her key ID is '''0x''' followed by the last 8 characters of the fingerprint &amp;amp;ndash; namely, '''0x63FEE659'''.	&lt;br /&gt;
#**GNU Privacy Assistant:&lt;br /&gt;
#**#In the '''Key Manager''', click the '''Preferences''' button (or select it from the Edit menu). The address &amp;lt;code&amp;gt;hkp://keys.gnupg.net&amp;lt;/code&amp;gt; should be filled in the '''Default keyserver''' field. Click OK.	&lt;br /&gt;
#**#Click the '''Server''' menu and select '''Retrieve keys'''. A small dialog box should pop up. Input &amp;lt;code&amp;gt;0x63FEE659&amp;lt;/code&amp;gt; for '''Key ID'''. Click OK.&lt;br /&gt;
#**#If the key is found, it will be automatically imported to your keyring.&lt;br /&gt;
#**Kleopatra:&lt;br /&gt;
#**#Click the '''Settings''' menu and select '''Configure Kleopatra'''. When the Configure window comes up, go to the '''Directory Services''' section. You should see &amp;amp;ldquo;hkp://keys.gnupg.net&amp;amp;rdquo; listed with the scheme &amp;amp;ldquo;hkp&amp;amp;rdquo; and the &amp;amp;ldquo;OpenGPG&amp;amp;rdquo; box checked. Click OK.&lt;br /&gt;
#**#With the main window in focus, click the '''Lookup Certificates on Server''' button (with a picture of binoculars), or select it from the File menu. The Certificate Lookup window should pop up.&lt;br /&gt;
#**#Input &amp;lt;code&amp;gt;0x63FEE659&amp;lt;/code&amp;gt; in the '''Find''' field and click '''Search'''.	&lt;br /&gt;
#**#If the key is found, select it and click '''Import''' to import it to your keyring.&lt;br /&gt;
#**Command line:&amp;lt;br /&amp;gt;Type &amp;lt;code&amp;gt;gpg --keyserver hkp://keys.gnupg.net --recv-keys 0x63fee659&amp;lt;/code&amp;gt;&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;	&lt;br /&gt;
#*'''Obtaining Erinn's key in person'''&amp;lt;br /&amp;gt;This is considered the most secure, although she is an individual and cannot always give out her key to the thousands of people who use Tor regularly.&amp;lt;br /&amp;gt;Since Erinn is a Debian developer, you might be able to meet her at a free software, open source software, or Linux IT conference. Hopefully there will be a sign somewhere displaying a hardcopy of her key. In that case, you can transcribe it to a keyfile (see below). If not, then maybe you can agree on another way to transfer it (such as a [http://www.gnupg.org/documentation/howtos.en.html key-signing party]).&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;	&lt;br /&gt;
#*'''Importing the key from a keyfile'''&amp;lt;br /&amp;gt;Generally, the keyfile is obtained either in person (see above), by asking someone else to export it from a keyring (&amp;lt;code&amp;gt;gpg --export -a 0x63fee659 &amp;gt; erinn_clark.asc&amp;lt;/code&amp;gt;), through a dedicated URL (for example, http://www.cacert.org/certs/cacert.asc) or by copying-and-pasting from a webpage (for example, http://dev.mysql.com/doc/refman/5.0/en/checking-gpg-signature.html).&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;There is a keyfile at http://deb.torproject.org/archive-key.asc which is used to verify the [http://deb.torproject.org/torproject.org/dists/ checksums] of the [http://deb.torproject.org/torproject.org/pool/main/ Debian and Ubuntu GNU/Linux versions of Tor and Vidalia]. For other operating systems (such as Windows or Mac OS), the key must be obtained using another method.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;Once the user has a keyfile, the key may be imported in the following manner:&lt;br /&gt;
#**GNU Privacy Assistant:&lt;br /&gt;
#**#In the '''Key Manager''', click the '''Import''' button. A file selector should pop up.&lt;br /&gt;
#**#Locate the file then click '''Open'''. The key should be automatically imported.&lt;br /&gt;
#**Kleopatra:&lt;br /&gt;
#***Drag-and-drop the file into the main window. A context menu pops up. Choose '''Import Certificates''', or&lt;br /&gt;
#***Click the '''Import Certificates''' button, or select it from the File menu. A file selector should pop up.&amp;lt;br /&amp;gt;Locate the file then click '''Open'''. The key should be automatically imported.&lt;br /&gt;
#**Command line:&amp;lt;br /&amp;gt;Type &amp;lt;code&amp;gt;gpg --import &amp;lt;/code&amp;gt; followed by the name of the signature file and press &amp;lt;ENTER&amp;gt;. A modern console emulator will allow you to drag-and-drop the file instead of typing out its name.&amp;lt;br /&amp;gt;&amp;lt;br /&amp;gt;&lt;br /&gt;
#'''Double-check the key's fingerprint'''&amp;lt;br /&amp;gt;You will do this by physically reading it.&lt;br /&gt;
#*GNU Privacy Assistant:&lt;br /&gt;
#*#In the '''Key Manager''', click the '''Key ID''' column to sort the keys numerically by ID.&lt;br /&gt;
#*#Scroll until you reach an item with ID number '''63FEE659'''. It should have the name '''Erinn Clark &amp;lt;erinn@torproject.org&amp;gt;'''.&lt;br /&gt;
#*#Select that item.&lt;br /&gt;
#*#In the '''Details''' tab below, you should see a row that says '''Key ID: 63FEE659'''.&lt;br /&gt;
#*#Check that the row below it says: '''Fingerprint: 8738 A680 B84B 3031 A630  F2DB 416F 0610 63FE E659'''&lt;br /&gt;
#*Kleopatra:&lt;br /&gt;
#*#After importing the key, it should be listed in a new tab named '''Imported Certificates'''. If not, then open a new tab with the &amp;amp;ldquo;All Certificates&amp;amp;rdquo; option.&lt;br /&gt;
#*#Look for an item with Key-ID '''63FEE659'''.&lt;br /&gt;
#*#Get the key's properties by either:&lt;br /&gt;
#*#*Double-clicking the item,&lt;br /&gt;
#*#*Right clicking the item and choosing '''Certificate Details''', or&lt;br /&gt;
#*#*Selecting the item, going to the '''View''' menu, then selecting '''Certificate Details'''&lt;br /&gt;
#*Command line:&amp;lt;br /&amp;gt;&lt;br /&gt;
#*#Type &amp;lt;code&amp;gt;gpg --fingerprint 0x63fee659&amp;lt;/code&amp;gt;&lt;br /&gt;
#*#Check that the program prints the following:&amp;lt;br /&amp;gt;&lt;br /&gt;
&amp;lt;pre style=&amp;quot;width: 60em&amp;quot;&amp;gt;&lt;br /&gt;
pub   2048R/63FEE659 2003-10-16&lt;br /&gt;
      Key fingerprint = 8738 A680 B84B 3031 A630  F2DB 416F 0610 63FE E659&lt;br /&gt;
uid                  Erinn Clark &amp;lt;erinn@torproject.org&amp;gt;&lt;br /&gt;
uid                  Erinn Clark &amp;lt;erinn@debian.org&amp;gt;&lt;br /&gt;
uid                  Erinn Clark &amp;lt;erinn@double-helix.org&amp;gt;&lt;br /&gt;
sub   2048R/EB399FD7 2003-10-16&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Admin</name></author>
		
	</entry>
</feed>