【发布时间】:2014-12-03 08:16:28
【问题描述】:
我是密码学的新手,我对主键指纹有疑问:
我已经下载了 Apache Maven,正如他们在下载页面中所说,我已经使用 gpg 验证了公钥的签名:
user$ gpg --verify apache-maven-3.2.3-bin.tar.gz.asc apache-maven-3.2.3-bin.tar.gz
gpg: Signature made Tue Aug 12 00:59:35 2014 MSK using DSA key ID BB617866
gpg: Good signature from "Someone <email@maven.org>"
gpg: WARNING: This key is not certified with a trusted signature!
gpg: There is no indication that the signature belongs to the owner.
Primary key fingerprint: FB11 D4BB 7B24 4678 337A AD8B C7BF 26D0 BB61 7866
现在,我从http://www.apache.org/dev/release-signing#fingerprint 读到,主键指纹是键的摘要,更易于阅读和比较,但我的问题是:
我应该如何比较它?我的意思是,我应该在哪里找到我应该比较指纹“FB11 D4BB 7B24 4678 337A AD8B C7BF 26D0 BB61 7866”的对应对象?
【问题讨论】:
标签: maven cryptography gnupg