Actions

Download the Signing Key for Whonix ™ KVM

From Whonix

< KVM



Introduction[edit]

Since all Whonix ™ KVM releases are signed with the same key, it is unnecessary to verify the key every time a new release is announced. Trust in the key might gradually increase over time, but cryptographic signatures must still be verified every time a new release is downloaded.

This page is strongly related to the Placing Trust in Whonix ™ page.

Download the OpenPGP Key[edit]

Optional: Complete the steps below if unfamiliar with GnuPG or if they haven't already been performed. This will fix eventual gpg: WARNING: unsafe ownership warnings.

Have GnuPG initialize your user data folder.

gpg --fingerprint

Set warning free permissions.

chmod --recursive og-rwx ~/.gnupg

1. Securely download Whonix ™ KVM developer HulaHoop's OpenPGP key. [1]
hulahoop.asc

2. Store the key as hulahoop.asc.

3. Check fingerprints/owners without importing anything. [2]

gpg --keyid-format long --import --import-options show-only --with-fingerprint hulahoop.asc

4. Verify the output.

The output should be identical to the following.

gpg: key 50C78B6F9FF2EC85: 1 signature not checked due to a missing key
pub   rsa4096/50C78B6F9FF2EC85 2018-11-26 [SCEA]
      Key fingerprint = 04EF 2F66 6D36 C354 058B  9DD4 50C7 8B6F 9FF2 EC85
uid                            HulaHoop
sub   rsa4096/EB27D2F8CEE41ACC 2018-11-26 [SEA]

The message gpg: key 50C78B6F9FF2EC85: 1 signature not checked due to a missing key is related to the The OpenPGP Web of Trust. Advanced users can learn more about this below.

5. Import the key.

gpg --import hulahoop.asc

The output should confirm the key was imported.

gpg: key 0x50C78B6F9FF2EC85: public key "HulaHoop" imported
gpg: Total number processed: 1
gpg:               imported: 1

If the Whonix ™ signing key was already imported in the past, the output should confirm the key is unchanged.

gpg: key 0x50C78B6F9FF2EC85: "HulaHoop" not changed
gpg: Total number processed: 1
gpg:              unchanged: 1

If the following message appears at the end of the output.

gpg: no ultimately trusted keys found

This extra message does not relate to the Whonix ™ signing key itself, but instead usually means the user has not created an OpenPGP key yet, which is of no importance when verifying virtual machine images.

Analyze the other messages as usual.

6. Advanced users can check Web of Trust further below for better security.

7. Complete the Whonix ™ verification steps.

If verifying Whonix ™ images, navigate to the relevant verification page below to finish the process:

Advanced Users[edit]

OpenPGP Web of Trust[edit]

Ambox warning pn.svg.png Advanced users only!

HulaHoop's OpenPGP key can be verified through The OpenPGP Web of Trust. Whonix ™ Patrick Schleizer's (adrelanos') has OpenPGP signed Whonix ™ KVM developer HulaHoop's OpenPGP key.

1. First, acquire Patrick's signing key.

Refer the the more secure, detailed Whonix ™ Main, VirtualBox, APT Repository and Source Code Signing Key instructions.

2. Verify the key was also signed by Whonix ™ lead developer Patrick Schleizer.

gpg --check-sigs "04EF 2F66 6D36 C354 058B 9DD4 50C7 8B6F 9FF2 EC85"

The output should be identical to the message below.

pub   rsa4096/0x50C78B6F9FF2EC85 2018-11-26 [SCEA]
      04EF2F666D36C354058B9DD450C78B6F9FF2EC85
uid                   [ unknown] HulaHoop
sig!         0x8D66066A2EEACCDA 2018-12-14  Patrick Schleizer <adrelanos@riseup.net>
sig!3        0x50C78B6F9FF2EC85 2018-11-26  HulaHoop
sub   rsa4096/0xEB27D2F8CEE41ACC 2018-11-26 [SEA]
sig!         0x50C78B6F9FF2EC85 2018-11-26  HulaHoop

gpg: 3 good signatures

Download the signify Key[edit]

Info Advanced users only!

[3]

untrusted comment: signify public key
RWT2GZDQkp1NtTAC1IoQHUsyb/AQ2LIQF82cygQU+riOpPWSq730A/rq

Further Reading[edit]

Troubleshooting[edit]

When a GPG error is encountered, first try a web search for the relevant error. The security stackexchange website [archive] can also help to resolve GPG problems. Describe the problem thoroughly, but be sure it is GPG-related and not specific to Whonix ™.

More help resources are available on the Support page.

See Also[edit]

License[edit]

Whonix ™ KVM/Whonix Signing Key wiki page Copyright (C) Amnesia <amnesia at boum dot org>
Whonix ™ KVM/Whonix Signing Key wiki page Copyright (C) 2012 - 2020 ENCRYPTED SUPPORT LP <adrelanos@whonix.org>

This program comes with ABSOLUTELY NO WARRANTY; for details see the wiki source code.
This is free software, and you are welcome to redistribute it under certain conditions; see the wiki source code for details.

Footnotes[edit]

  1. curl --tlsv1.2 --proto =https --max-time 180 --output ~/hulahoop.asc https://www.whonix.org/hulahoop.asc

  2. https://forums.whonix.org/t/gpg-show-key-warning-gpg-warning-no-command-supplied-trying-to-guess-what-you-mean/7859 [archive]
  3. -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512
    
    untrusted comment: signify public key
    RWT2GZDQkp1NtTAC1IoQHUsyb/AQ2LIQF82cygQU+riOpPWSq730A/rq
    -----BEGIN PGP SIGNATURE-----
    
    iQKTBAEBCgB9FiEEZvRiRskAcH/xDcHk6yfS+M7kGswFAl9FA2ZfFIAAAAAALgAo
    aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDY2
    RjQ2MjQ2QzkwMDcwN0ZGMTBEQzFFNEVCMjdEMkY4Q0VFNDFBQ0MACgkQ6yfS+M7k
    Gsx0Ig//XIWcAU6FEy5BOPZp7mG6kGYUXJJNrMQzIW8JK49TlwHIRM6JjilUmn07
    pV0Gq7RKAs9gLZWa4YbygUj0wZcaILLaqsmF0Np0mJuhkADiQVCJbLbrPanJACqy
    cs/3ALqqVEYHmZgtmQzWGKOiwHF+g4UtSmr4iNo2ykssGfcx/FHifisoeRe/Bku1
    E++Z01kwIesQbETMF9x/PakxEHl0hCAES9ReRXhoDj87i4BEzqVa8m+/PS7woQEQ
    U6NA28ANreIpHYdQ2vGnWFc6JIrf5B10QVPd0JOwEO2w9efeVpgdCUNhA/SBx3jo
    j0kZZsF9gGuybrSysd7Ftn9XxA/S5rmWOzIL2miRbSrZpd2n5k0zlhyZoHGVKg3S
    bDhZr+Cw4BMMpiRcTtm11XwHcPDB4DkQL5MMrb+ISDe9Xy+zcEkGGY3da9JcNSQ8
    6F9PziVyyO1jnOruZSoEmrB+vdKFl/yO007IIeByPCcsGdr1ITyEd6LAByV5SzxI
    Xp98gOO07rwrH6rUYSE75ErRwqQM9pKoVCZQbTantss+6kXLxxXDSFbkmRmyBTVS
    3+kyshd53CQSsShb9lwroBSQJEj/Rfh+X8bvZe7sQFKY9/3GT5fktEteY1qkOSX7
    HYttYy0gOeaawq8RhRxN+l3oOi9Zwll3kOpagj5xvNyrfwayp/E=
    =2wdp
    -----END PGP SIGNATURE-----
    
    


text=Jobs in USA
Jobs in USA


Search engines: YaCy | Qwant | ecosia | MetaGer | peekier | Whonix ™ Wiki


Follow: Twitter.png Facebook.png Rss.png Matrix logo.svg.png 1024px-Telegram 2019 Logo.svg.png Discourse logo.png Reddit.jpg 200px-Mastodon Logotype (Simple).svg.png

Donate: Donate Bank Wire Paypal Bitcoin accepted here Monero accepted here Contriute

Whonix donate bitcoin.png Monero donate Whonix.png United Federation of Planets 1000px.png

Share: Twitter | Facebook

Want to get involved with Whonix ™? Check out our Contribute [archive] page.

https link onion link

This is a wiki. Want to improve this page? Help is welcome and volunteer contributions are happily considered! Read, understand and agree to Conditions for Contributions to Whonix ™, then Edit! Edits are held for moderation. Policy of Whonix Website and Whonix Chat and Policy On Nonfreedom Software applies.

Copyright (C) 2012 - 2020 ENCRYPTED SUPPORT LP. Whonix ™ is a trademark. Whonix ™ is a licensee [archive] of the Open Invention Network [archive]. Unless otherwise noted, the content of this page is copyrighted and licensed under the same Freedom Software license as Whonix ™ itself. (Why?)

Whonix ™ is a derivative of and not affiliated with Debian [archive]. Debian is a registered trademark [archive] owned by Software in the Public Interest, Inc [archive].

Whonix ™ is produced independently from the Tor® [archive] anonymity software and carries no guarantee from The Tor Project [archive] about quality, suitability or anything else.

By using our website, you acknowledge that you have read, understood and agreed to our Privacy Policy, Cookie Policy, Terms of Service, and E-Sign Consent. Whonix ™ is provided by ENCRYPTED SUPPORT LP. See Imprint, Contact.