Re: [opensuse] KGPG shows invalid fingerprints

But I need fingerprints to verify the correct transmission of public keys. The correct fingerprint of the SUSE Security Team is (see https://en.opensuse.org/openSUSE:Security_team): pub 4096R/317CD502 2014-10-02 Key fingerprint = E502 243D F6B7 E939 EA1B 4A0E 58FC 58B1 317C D502 uid [ full ] SUSE Security Team <security@suse.de> sub 4096R/0DE80E03 2014-10-02 My gpg2 command line tools shows this fingerprint, but KGPG shows something else (C2FE 18E6 D4A7 021A 787C B734 4574 4695 0DE8 0E03). I'd like to verify that other users also see a wrong fingerprint in KGPG before filing a bug report. Greetings, Björn -- To unsubscribe, e-mail: opensuse+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse+owner@opensuse.org

On 09/10/2015 01:22 PM, Bjoern Voigt wrote:
What (exactly) was your kgpg command line? -- After all is said and done, more is said than done. -- To unsubscribe, e-mail: opensuse+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse+owner@opensuse.org

John Andersen wrote:
bjoernv 3103 0.0 0.0 565596 8328 ? S 08:59 0:01 kdeinit4: kglobalaccel [kdeinit] bjoernv 3285 0.0 0.0 701816 10836 ? Sl 08:59 0:07 /usr/bin/kget -session 10153faa1ee000141518136900000037380038_1441836163_895700 The GnuPG Setting in Settings -> Configure KGpg -> GnuPG Settings are: Home location: /home/bjoernv/.gnupg/ Configuration file: gpg.conf Program path: gpg2 [v] Use GnuPG agent Greetings, Björn -- To unsubscribe, e-mail: opensuse+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse+owner@opensuse.org

On 09/10/2015 02:09 PM, Bjoern Voigt wrote:
Well, I was really asking where you got the output of KGpg that you wanted us to confirm for you. After digging around: in the KGpg window, which I found residing in the KDE4 Tray And selecting the Security Team entry that has an email address of security@suse.com, avoiding the entry with security@suse.de, Then right clicking and selecting Key Properties, I finally find output similar to the output you show above, but which you never explained how to get to. When I do all those steps I see key Id 58FC58B1317CD502 ... Fingerprint E502 243D F6B7 E939 EA1B 4A0E 58FC 58B1 317C D502 -- After all is said and done, more is said than done. -- To unsubscribe, e-mail: opensuse+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse+owner@opensuse.org

On 09/11/2015 02:45 AM, Bjoern Voigt wrote:
Well, as I mentioned ABOVE, I selected security@suse.com. You selected security@suse.de You have two entries for security@suse.de. I have one each for de and com. In your image The first security@suse.de is a 2048bit The 2nd security@suse.de is a 4096bit In my system security@suse.de is a 2048 bit key. security@suse.com is a 4096 bit key It would seem that your imported keys are fundamentally different than mine. I may just nuke both of those keys and import them again. None of mine are fully trusted. -- After all is said and done, more is said than done.

John, On 09/11/2015 07:28 PM, John Andersen wrote: < attachment > Set font hinting to slight ;-). -- To unsubscribe, e-mail: opensuse+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse+owner@opensuse.org

Bjoern Voigt wrote:
I exported the three shown keys (2x security@suse.de, security-officer@FreeBSD.org) and my own keys (with public and private key) which used for signing the three keys. The other users KGPG shows the correct fingerprints. So it's difficult to create a minimal keyring for testing without all my private keys. Greetings, Björn -- To unsubscribe, e-mail: opensuse+unsubscribe@opensuse.org To contact the owner, e-mail: opensuse+owner@opensuse.org
participants (3)
-
Bjoern Voigt
-
John Andersen
-
Xen