FALSCHE Unterschrift von "Werner Koch (gnupg sig) <dd9jn@gnu.org>"

Frank Derichsweiler fd-l-gpg@daidalos.informatik.unibw-muenchen.de
Mon, 13 Nov 2000 09:10:39 +0100

On Sun, Nov 12, 2000 at 11:08:41PM +0100, Joerg Soos wrote:

> So what i've done wrong, because can't believe that they have
> something wrong on their servers.
I assume you have a download-Problem (i.e. ascii vs. binary)
> jws@linux:~ > md5sum privacy_tars/gnupg-1.0.4.tar.gz
> 8db4fe7df0b9d8535e4ff6fc7611a56c privacy_tars/gnupg-1.0.4.tar.gz
I get the following: md5sum gnupg-1.0.4.tar.gz bef2267bfe9b74a00906a78db34437f9 gnupg-1.0.4.tar.gz Trying to verify gives: gpg --verify gnupg-1.0.4.tar.gz.sig gpg: Warning: using insecure memory! gpg: Signature made Tue Oct 17 17:31:27 2000 MEST using DSA key ID 57548DCD gpg: Good signature from "Werner Koch (gnupg sig) <dd9jn@gnu.org>" Could not find a valid trust path to the key. Let's see whether we can assign some missing owner trust values. No path leading to one of our keys found. gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. gpg: Fingerprint: 6BD9 050F D8FC 941B 4341 2DCC 68B7 AB89 5754 8DCD HTH Frank