Difference between revisions of "How-to verify GPG key of official .ISO images"
Views
Actions
Namespaces
Variants
Tools
(Marked this version for translation) |
m (The gpg --verify command should have 2 arguments: the ".sig" file and the manjaro ".iso" file.) |
||
Line 25: | Line 25: | ||
<!--T:7--> | <!--T:7--> | ||
'''4.''' Finally, verify if the .iso image file was built by the Manjaro Build Server, Philip Müller or one of the other Manjaro Developers | '''4.''' Finally, verify if the .iso image file was built by the Manjaro Build Server, Philip Müller or one of the other Manjaro Developers: | ||
gpg --verify manjaro-ISO-image.iso.sig | gpg --verify manjaro-ISO-image.iso.sig manjaro-ISO-image.iso | ||
Compare the key which was used to sign the .iso file with the corresponding developer key. | Compare the key which was used to sign the .iso file with the corresponding developer key. | ||
Revision as of 15:23, 20 January 2022
1. Download an ISO file and the corresponding .sig file from the official sources (see Download Manjaro below).
2. Install GPG and wget using a Manjaro package manager (pamac or pacman):
pamac install gnupg wget
3. Next, you have 2 possible ways to import Manjaro's keys. Choose one of them:
Download all keys from the Manjaro Developers from GitLab:
wget gitlab.manjaro.org/packages/core/manjaro-keyring/-/raw/master/manjaro.gpg
Next, import all the keys in the downloaded .gpg file into your gnupg keyring:
gpg --import manjaro.gpg
If you do not trust GitLab, import the Manjaro Build Server's GPG key to your system (afterwards, select the key by entering its number and pressing ENTER):
gpg --keyserver keyserver.ubuntu.com --search-keys Manjaro Build Server
4. Finally, verify if the .iso image file was built by the Manjaro Build Server, Philip Müller or one of the other Manjaro Developers:
gpg --verify manjaro-ISO-image.iso.sig manjaro-ISO-image.iso
Compare the key which was used to sign the .iso file with the corresponding developer key.
Check whether the .ISO was verified by Philip Müller's GPG key, another Manjaro Developer's key, or the Manjaro Build Server key which you have imported to your system. If this is the case, you can be sure that your .iso is official.