Re: verifying the boot.iso for fedora 15

2011-04-05 Thread Ed Greshko
On 04/06/2011 10:14 AM, Ed Greshko wrote: > > gpg: Signature made Thu 03 Mar 2011 11:34:51 AM CST using RSA key ID > 069C8460 > gpg: Good signature from "Fedora (15) " > gpg: WARNING: This key is not certified with a trusted signature! > gpg: There is no indication that the signature belon

Re: verifying the boot.iso for fedora 15

2011-04-05 Thread Joel Rees
Ah! On Wed, Apr 6, 2011 at 11:33 AM, Ed Greshko wrote: > On 04/06/2011 10:22 AM, Joel Rees wrote: >> Okay, Trying to verify the alpha netinst.iso, I seem to have forgotten >> the way these files work, again. > > Step 1 is to verify the signature on the CHECKSUM file > > gpg --verify *-CHECKSU

Re: verifying the boot.iso for fedora 15

2011-04-05 Thread Joel Rees
On Wed, Apr 6, 2011 at 10:38 AM, Todd Zullinger wrote: > Joel Rees wrote: >> gpg: Signature made Thu 03 Mar 2011 12:34:51 PM JST using RSA key ID 069C8460 >> gpg: Good signature from "Fedora (15) " >> gpg: WARNING: This key is not certified with a trusted signature! >> gpg:          There is no in

Re: verifying the boot.iso for fedora 15

2011-04-05 Thread Ed Greshko
On 04/06/2011 10:22 AM, Joel Rees wrote: > Okay, Trying to verify the alpha netinst.iso, I seem to have forgotten > the way these files work, again. Step 1 is to verify the signature on the CHECKSUM file gpg --verify *-CHECKSUM That gives you confidence that the data in that file comes from

Re: verifying the boot.iso for fedora 15

2011-04-05 Thread Joel Rees
Okay, Trying to verify the alpha netinst.iso, I seem to have forgotten the way these files work, again. gpg --verify Fedora-15-Alpha-i386-CHECKSUM Fedora-15-Alpha-i386-netinst.iso gpg: not a detached signature --- This is telling me that the CHECKSUM combines the signature and the checksum.

Re: verifying the boot.iso for fedora 15

2011-04-05 Thread Ed Greshko
On 04/06/2011 09:38 AM, Todd Zullinger wrote: > > I just pushed a fix for this to the fedora-web git repository¹. When > the website syncs next it should be on the /keys page. That is the > proper key and fingerprint (though I don't expect you to just take my > word for that ;). > > The key file

Re: verifying the boot.iso for fedora 15

2011-04-05 Thread Todd Zullinger
Joel Rees wrote: > gpg: Signature made Thu 03 Mar 2011 12:34:51 PM JST using RSA key ID 069C8460 > gpg: Good signature from "Fedora (15) " > gpg: WARNING: This key is not certified with a trusted signature! > gpg: There is no indication that the signature belongs to the owner. > Primary ke

Re: verifying the boot.iso for fedora 15

2011-04-05 Thread Joel Rees
On Wed, Apr 6, 2011 at 12:14 AM, Ed Greshko wrote: > On 04/05/2011 11:12 PM, Ed Greshko wrote: >> On 04/05/2011 10:43 PM, Joel Rees wrote: >>> How does one verify boot.iso for the alpha version? >>> >>> I've imported the key file, but I don't see a proper signature or an >>> sha256 checksum. >> I

Re: verifying the boot.iso for fedora 15

2011-04-05 Thread Ed Greshko
On 04/05/2011 11:12 PM, Ed Greshko wrote: > On 04/05/2011 10:43 PM, Joel Rees wrote: >> How does one verify boot.iso for the alpha version? >> >> I've imported the key file, but I don't see a proper signature or an >> sha256 checksum. > I downloaded from a mirror and it was there > > e.g. > f

Re: verifying the boot.iso for fedora 15

2011-04-05 Thread Ed Greshko
On 04/05/2011 10:43 PM, Joel Rees wrote: > How does one verify boot.iso for the alpha version? > > I've imported the key file, but I don't see a proper signature or an > sha256 checksum. I downloaded from a mirror and it was there e.g. ftp://ftp.isu.edu.tw:0/pub/Linux/Fedora/linux/releases/