Bitcoin Forum
May 05, 2024, 08:43:06 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Proper way to verify GPG Signature using Kleopatra on Windows  (Read 10543 times)
dbasql (OP)
Full Member
***
Offline Offline

Activity: 219
Merit: 100


Ethics and Science need to shake hands


View Profile
September 19, 2013, 08:05:01 PM
 #1

I wanted to make this thread in hopes that the questions will be answered and it will help others. I am currently doing escrow with John K and there is some confusion from me and the buyer as to how to properly verify his sig.

Here is his public example

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hey everyone,

I figured that as I've been getting requests here and there for escrow services, it would be better that if I made a thread about this to consolidate the matter. I'm providing this service FOC and as a service for the community, but tips are graciously accepted for my time.

I will issue a contract signed by my GPG key below, with the Bitcoin address embedded within the message. Please do not accept a Bitcoin address that is not GPG signed. Anyone who has dealt with my escrow services before knows what to expect in my contract, of course.

On the event that any problems arises, I will release the escrow to whichever party that presents me with the most convincing proof after an open discussion with others and/or theymos. I've invoked this point twice only in my escrow 'lifetime' , and both resulted in a satisfactory settlement by all parties.

As always, PM me if you need me - I'm generally responsive if you see me online.

Best,
John 
Dated today: Feb 7 2013
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (MingW32)

iQIcBAEBAgAGBQJREyI7AAoJEINT5jezqu6wAPgQALDYQYOfd5q52cIz2I+7ojJ2
dclydx1YbLY/soMgGJS5H8QueklVoY0mV0OMYlTAX3vJB2woisvgXLjSz/OlqmSK
td79svGotNe92B7vZRT/q1MD3dW9d+vvl/v0Y5ol+j23c2JGZb5GLWypBg+fBBnw
9kg8mCIMTtAvZpxjB1icA2k5Otp+2Yawl1/5CDHn3TwkNvxMdVUmgmyPcv5jOsiN
Zx5ru6gOCjNWCMI/O1EW0QjG0j8VEVKFq0ysVHobnuD9q4MrDsHOf5m6XCjQ5/s3
oBFI+ybP395AcsTg0eLNzPhDu6EbvcCh4J2vhPhXIo/z4iLrW3TWsEV0sq+RTc6+
kL7LHqOQSZM+clTJTM55+7RcRgJuAUsG+TMfEogoGbL7ysYrMupta1e82nflwp08
crjBR2dCx1uX5qYGw+IPy1BOF2AvHKOrMCUIJVeVyIa9g5ynikEP3hWWOjWmQBMv
wRVMWoarvOtbX3W4ZEG7wq2TKeqgBOFm0FPqfwBGlzFjMR2Ge9qhG3MO0eRtrxgN
z1gtBPH3ha/IO6CS3uyvK1X3oq6zJY89Ty6jX3QcHzuWyBly3BX+MPVm/apRZAvX
hBaok54h/yoV5pRCOpnKl5kPwYoYWiSi8pgWm0fIyvrTRWm2dS5gtDQBuZdGPnVx
c5w6azyMJ0M79X4s9RiN
=06T4
-----END PGP SIGNATURE-----

If I wanted to  create the steps what would they be?
1) download and install Kleopatra
2) create a .asc file with ?
3) verify message against that file ?
4) ?

etc....

Thanks
DBA
Transactions must be included in a block to be properly completed. When you send a transaction, it is broadcast to miners. Miners can then optionally include it in their next blocks. Miners will be more inclined to include your transaction if it has a higher transaction fee.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714941786
Hero Member
*
Offline Offline

Posts: 1714941786

View Profile Personal Message (Offline)

Ignore
1714941786
Reply with quote  #2

1714941786
Report to moderator
1714941786
Hero Member
*
Offline Offline

Posts: 1714941786

View Profile Personal Message (Offline)

Ignore
1714941786
Reply with quote  #2

1714941786
Report to moderator
1714941786
Hero Member
*
Offline Offline

Posts: 1714941786

View Profile Personal Message (Offline)

Ignore
1714941786
Reply with quote  #2

1714941786
Report to moderator
Newar
Legendary
*
Offline Offline

Activity: 1358
Merit: 1000


https://gliph.me/hUF


View Profile
September 20, 2013, 05:04:25 AM
 #2

I wanted to make this thread in hopes that the questions will be answered and it will help others. I am currently doing escrow with John K and there is some confusion from me and the buyer as to how to properly verify his sig.

Here is his public example

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hey everyone,

I figured that as I've been getting requests here and there for escrow services, it would be better that if I made a thread about this to consolidate the matter. I'm providing this service FOC and as a service for the community, but tips are graciously accepted for my time.

I will issue a contract signed by my GPG key below, with the Bitcoin address embedded within the message. Please do not accept a Bitcoin address that is not GPG signed. Anyone who has dealt with my escrow services before knows what to expect in my contract, of course.

On the event that any problems arises, I will release the escrow to whichever party that presents me with the most convincing proof after an open discussion with others and/or theymos. I've invoked this point twice only in my escrow 'lifetime' , and both resulted in a satisfactory settlement by all parties.

As always, PM me if you need me - I'm generally responsive if you see me online.

Best,
John 
Dated today: Feb 7 2013
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (MingW32)

iQIcBAEBAgAGBQJREyI7AAoJEINT5jezqu6wAPgQALDYQYOfd5q52cIz2I+7ojJ2
dclydx1YbLY/soMgGJS5H8QueklVoY0mV0OMYlTAX3vJB2woisvgXLjSz/OlqmSK
td79svGotNe92B7vZRT/q1MD3dW9d+vvl/v0Y5ol+j23c2JGZb5GLWypBg+fBBnw
9kg8mCIMTtAvZpxjB1icA2k5Otp+2Yawl1/5CDHn3TwkNvxMdVUmgmyPcv5jOsiN
Zx5ru6gOCjNWCMI/O1EW0QjG0j8VEVKFq0ysVHobnuD9q4MrDsHOf5m6XCjQ5/s3
oBFI+ybP395AcsTg0eLNzPhDu6EbvcCh4J2vhPhXIo/z4iLrW3TWsEV0sq+RTc6+
kL7LHqOQSZM+clTJTM55+7RcRgJuAUsG+TMfEogoGbL7ysYrMupta1e82nflwp08
crjBR2dCx1uX5qYGw+IPy1BOF2AvHKOrMCUIJVeVyIa9g5ynikEP3hWWOjWmQBMv
wRVMWoarvOtbX3W4ZEG7wq2TKeqgBOFm0FPqfwBGlzFjMR2Ge9qhG3MO0eRtrxgN
z1gtBPH3ha/IO6CS3uyvK1X3oq6zJY89Ty6jX3QcHzuWyBly3BX+MPVm/apRZAvX
hBaok54h/yoV5pRCOpnKl5kPwYoYWiSi8pgWm0fIyvrTRWm2dS5gtDQBuZdGPnVx
c5w6azyMJ0M79X4s9RiN
=06T4
-----END PGP SIGNATURE-----

If I wanted to  create the steps what would they be?
1) download and install Kleopatra
2) create a .asc file with ?
3) verify message against that file ?
4) ?

etc....

Thanks
DBA


IIRC: get the public key of the sender. Then copy the whole thing in your clipboard. Right click the Kleopatra icon in the task bar. It will give you the option to verify the sig from clipboard.

Under Windows I preferred Cryptophane.

OTC rating | GPG keyid 1DC91318EE785FDE | Gliph: lightning bicycle tree music | Mycelium, a swift & secure Bitcoin client for Android | LocalBitcoins
dbasql (OP)
Full Member
***
Offline Offline

Activity: 219
Merit: 100


Ethics and Science need to shake hands


View Profile
September 20, 2013, 08:23:28 PM
 #3

I wanted to make this thread in hopes that the questions will be answered and it will help others. I am currently doing escrow with John K and there is some confusion from me and the buyer as to how to properly verify his sig.

Here is his public example

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hey everyone,

I figured that as I've been getting requests here and there for escrow services, it would be better that if I made a thread about this to consolidate the matter. I'm providing this service FOC and as a service for the community, but tips are graciously accepted for my time.

I will issue a contract signed by my GPG key below, with the Bitcoin address embedded within the message. Please do not accept a Bitcoin address that is not GPG signed. Anyone who has dealt with my escrow services before knows what to expect in my contract, of course.

On the event that any problems arises, I will release the escrow to whichever party that presents me with the most convincing proof after an open discussion with others and/or theymos. I've invoked this point twice only in my escrow 'lifetime' , and both resulted in a satisfactory settlement by all parties.

As always, PM me if you need me - I'm generally responsive if you see me online.

Best,
John 
Dated today: Feb 7 2013
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (MingW32)

iQIcBAEBAgAGBQJREyI7AAoJEINT5jezqu6wAPgQALDYQYOfd5q52cIz2I+7ojJ2
dclydx1YbLY/soMgGJS5H8QueklVoY0mV0OMYlTAX3vJB2woisvgXLjSz/OlqmSK
td79svGotNe92B7vZRT/q1MD3dW9d+vvl/v0Y5ol+j23c2JGZb5GLWypBg+fBBnw
9kg8mCIMTtAvZpxjB1icA2k5Otp+2Yawl1/5CDHn3TwkNvxMdVUmgmyPcv5jOsiN
Zx5ru6gOCjNWCMI/O1EW0QjG0j8VEVKFq0ysVHobnuD9q4MrDsHOf5m6XCjQ5/s3
oBFI+ybP395AcsTg0eLNzPhDu6EbvcCh4J2vhPhXIo/z4iLrW3TWsEV0sq+RTc6+
kL7LHqOQSZM+clTJTM55+7RcRgJuAUsG+TMfEogoGbL7ysYrMupta1e82nflwp08
crjBR2dCx1uX5qYGw+IPy1BOF2AvHKOrMCUIJVeVyIa9g5ynikEP3hWWOjWmQBMv
wRVMWoarvOtbX3W4ZEG7wq2TKeqgBOFm0FPqfwBGlzFjMR2Ge9qhG3MO0eRtrxgN
z1gtBPH3ha/IO6CS3uyvK1X3oq6zJY89Ty6jX3QcHzuWyBly3BX+MPVm/apRZAvX
hBaok54h/yoV5pRCOpnKl5kPwYoYWiSi8pgWm0fIyvrTRWm2dS5gtDQBuZdGPnVx
c5w6azyMJ0M79X4s9RiN
=06T4
-----END PGP SIGNATURE-----

If I wanted to  create the steps what would they be?
1) download and install Kleopatra
2) create a .asc file with ?
3) verify message against that file ?
4) ?

etc....

Thanks
DBA


IIRC: get the public key of the sender. Then copy the whole thing in your clipboard. Right click the Kleopatra icon in the task bar. It will give you the option to verify the sig from clipboard.

Under Windows I preferred Cryptophane.

Thanks I will look at that.
I am trying to dumb it down even further so someone that has never done this at all can do it and feel confident.

1) save message text as ....
2) save signature text as ...
3) Your suggestion to go to IRC (
IIRC: get the public key of the sender. Then copy the whole thing in your clipboard. Right click the Kleopatra icon in the task bar. It will give you the option to verify the signature from clipboard.)

Newar
Legendary
*
Offline Offline

Activity: 1358
Merit: 1000


https://gliph.me/hUF


View Profile
September 21, 2013, 02:01:24 AM
 #4

I wanted to make this thread in hopes that the questions will be answered and it will help others. I am currently doing escrow with John K and there is some confusion from me and the buyer as to how to properly verify his sig.

Here is his public example

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hey everyone,

I figured that as I've been getting requests here and there for escrow services, it would be better that if I made a thread about this to consolidate the matter. I'm providing this service FOC and as a service for the community, but tips are graciously accepted for my time.

I will issue a contract signed by my GPG key below, with the Bitcoin address embedded within the message. Please do not accept 9 Bitcoin address that is not GPG signed. Anyone who has dealt with my escrow services before knows what to expect in my contract, of course.

On the event that any problems arises, I will release the escrow to whichever party that presents me with the most convincing proof after an open discussion with others and/or theymos. I've invoked this point twice only in my escrow 'lifetime' , and both resulted in a satisfactory settlement by all parties.

As always, PM me if you need me - I'm generally responsive if you see me online.

Best,
John 
Dated today: Feb 7 2013
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (MingW32)

iQIcBAEBAgAGBQJREyI7AAoJEINT5jezqu6wAPgQALDYQYOfd5q52cIz2I+7ojJ2
dclydx1YbLY/soMgGJS5H8QueklVoY0mV0OMYlTAX3vJB2woisvgXLjSz/OlqmSK
td79svGotNe92B7vZRT/q1MD3dW9d+vvl/v0Y5ol+j23c2JGZb5GLWypBg+fBBnw
9kg8mCIMTtAvZpxjB1icA2k5Otp+2Yawl1/5CDHn3TwkNvxMdVUmgmyPcv5jOsiN
Zx5ru6gOCjNWCMI/O1EW0QjG0j8VEVKFq0ysVHobnuD9q4MrDsHOf5m6XCjQ5/s3
oBFI+ybP395AcsTg0eLNzPhDu6EbvcCh4J2vhPhXIo/z4iLrW3TWsEV0sq+RTc6+
kL7LHqOQSZM+clTJTM55+7RcRgJuAUsG+TMfEogoGbL7ysYrMupta1e82nflwp08
crjBR2dCx1uX5qYGw+IPy1BOF2AvHKOrMCUIJVeVyIa9g5ynikEP3hWWOjWmQBMv
wRVMWoarvOtbX3W4ZEG7wq2TKeqgBOFm0FPqfwBGlzFjMR2Ge9qhG3MO0eRtrxgN
z1gtBPH3ha/IO6CS3uyvK1X3oq6zJY89Ty6jX3QcHzuWyBly3BX+MPVm/apRZAvX
hBaok54h/yoV5pRCOpnKl5kPwYoYWiSi8pgWm0fIyvrTRWm2dS5gtDQBuZdGPnVx
c5w6azyMJ0M79X4s9RiN
=06T4
-----END PGP SIGNATURE-----

If I wanted to  create the steps what would they be?
1) download and install Kleopatra
2) create a .asc file with ?
3) verify message against that file ?
4) ?

etc....

Thanks
DBA


IIRC: get the public key of the sender. Then copy the whole thing in your clipboard. Right click the Kleopatra icon in the task bar. It will give you the option to verify the sig from clipboard.

Under Windows I preferred Cryptophane.

Thanks I will look at that.
I am trying to dumb it down even further so someone that has never done this at all can do it and feel confident.

1) save message text as ....
2) save signature text as ...
3) Your suggestion to go to IRC (
IIRC: get the public key of the sender. Then copy the whole thing in your clipboard. Right click the Kleopatra icon in the task bar. It will give you the option to verify the signature from clipboard.)



You don't need to save the message or signature text, just use the clipboard.

IIRC stands for "if I remember correctly".

OTC rating | GPG keyid 1DC91318EE785FDE | Gliph: lightning bicycle tree music | Mycelium, a swift & secure Bitcoin client for Android | LocalBitcoins
dbasql (OP)
Full Member
***
Offline Offline

Activity: 219
Merit: 100


Ethics and Science need to shake hands


View Profile
October 11, 2013, 03:54:41 PM
 #5

Awesome Thanks for this will give it a go and this will help others I'm sure!
 Grin
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!