in reply to extracting original from gpg clearsigned file
Is this tar file from an email or something? Is it MIME::Base64 encoded, or encoded by another method, or is it binary?
PGP/GPG signed files should not modify the information between the
and-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
-----BEGIN PGP SIGNATURE-----
Sorry if I'm stating the obvious with this, but one thing that's just struck me, crazy though it is: you're not trying to get a file from something like
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (GNU/Linux) iD8dBQE8Rg1UOcb+EPeM7ggRApQSAJ0dqFfLKZ5QkRUAHJFZHcjJ5dV2-QCeOPEH ybtpRe\\KLR7bCdt0YOtcnk= =dugR -----END PGP SIGNATURE-----
That's only a signature which is sometimes distributed as another file - for example the linux kernel tarball has a kernel-2.x.x.tar.gz.sign file associated with it, which contains the PGP signature for the kernel tarball.
You use that file with PGP/GPG to check that the (in this example) kernel tarball hasn't been changed - similar to checking an md5sum - the tarball isn't part of that GPG signature!
All the signature tells you is which key/who signed it, and gives some checksum information for the file you should check it against.
Cheers
BazB.
|
|---|
| Replies are listed 'Best First'. | |
|---|---|
|
Re: Re: extracting original from gpg clearsigned file
by jmarans (Novice) on Jan 17, 2002 at 21:09 UTC |