Bitcoin Forum
May 04, 2024, 12:27:25 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Electrum Mac - Verify signature on electrum DMG - Not trusted -  (Read 112 times)
cr256 (OP)
Newbie
*
Offline Offline

Activity: 3
Merit: 5


View Profile
November 09, 2020, 08:06:32 AM
Merited by ABCbits (2), o_e_l_e_o (2)
 #1

Hi All. Im new to everything bitcoin. This is my first post.

I am trying to install electrum on my mac desktop. Downloaded GPG keychain, electrum dmg and electrum asc files.

Installed thomas V's key on GPG using key from here: https://bitzuma.com/posts/how-to-verify-an-electrum-download-on-mac/

When I attempt to verify signature of the electrum dmg file, it says 'untrusted file' 'signature not to be trusted'

Ive tried many times, downloading the files form electrum.org, reinstalling thomas v's key in GPG, but always the same response when i try to verify.

Can anyone offer any assistance? From what i see, the electrum.org dmg file is corrupted, but there's probably something I'm not doing right.

Thanks

Cor
1714825645
Hero Member
*
Offline Offline

Posts: 1714825645

View Profile Personal Message (Offline)

Ignore
1714825645
Reply with quote  #2

1714825645
Report to moderator
1714825645
Hero Member
*
Offline Offline

Posts: 1714825645

View Profile Personal Message (Offline)

Ignore
1714825645
Reply with quote  #2

1714825645
Report to moderator
Each block is stacked on top of the previous one. Adding another block to the top makes all lower blocks more difficult to remove: there is more "weight" above each block. A transaction in a block 6 blocks deep (6 confirmations) will be very difficult to remove.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1714825645
Hero Member
*
Offline Offline

Posts: 1714825645

View Profile Personal Message (Offline)

Ignore
1714825645
Reply with quote  #2

1714825645
Report to moderator
1714825645
Hero Member
*
Offline Offline

Posts: 1714825645

View Profile Personal Message (Offline)

Ignore
1714825645
Reply with quote  #2

1714825645
Report to moderator
Jating
Hero Member
*****
Offline Offline

Activity: 2912
Merit: 808


View Profile
November 09, 2020, 08:30:23 AM
 #2

I'm using a Mac myself but I didn't encounter any problem whatsoever. Maybe this thread can help you out.

[GUIDE] How to Safely Download and Verify Electrum [Guide].
How to verify your Electrum [Windows, Linux, Mac].

Or if you can't really find the answer, maybe you can go to this board and ask the question there: https://bitcointalk.org/index.php?board=98.0
cr256 (OP)
Newbie
*
Offline Offline

Activity: 3
Merit: 5


View Profile
November 10, 2020, 12:56:57 AM
Last edit: November 10, 2020, 01:59:14 AM by cr256
 #3

Thanks both of you. One last try on this thread. I used home-brew and got this message:

$ gpg --verify electrum-4.0.4.dmg.asc electrum-4.0.4.dmg
gpg: Signature made Fri 16 Oct 05:21:39 2020 AEDT
gpg:                using RSA key 6694D8DE7BE8EE5631BED9502BD5824B7F9470E6
gpg: key 2BD5824B7F9470E6: no user ID
gpg: Total number processed: 1
gpg: Can't check signature: No public key



When I use GPG Keychain it says - Untrusted signature. Thomas V ..... This signature is not to be trusted
It doesnt say Bad, or Error, just that is is Thomas V and not to be trusted.


So from another thread in this forum it says:

usually people don't add the key to their list of trusted keys so the verification result always has a warning that confuses most people. it is along the line of saying something like this:
Code:
gpg: WARNING: This key is not certified with a trusted signature!
gpg: There is no indication that the signature belongs to the owner.
sometimes people confuse this with the signature not being valid whereas all it says is that they key is not saved in their local database as a trusted key.



Does this mean it is ok?

Husna QA
Legendary
*
Offline Offline

Activity: 2268
Merit: 2863


#SWGT CERTIK Audited


View Profile WWW
November 10, 2020, 03:02:14 AM
Last edit: May 18, 2023, 06:39:06 AM by Husna QA
Merited by ABCbits (1)
 #4

-snip-
When I attempt to verify signature of the electrum dmg file, it says 'untrusted file' 'signature not to be trusted'

Ive tried many times, downloading the files form electrum.org, reinstalling thomas v's key in GPG, but always the same response when i try to verify.
-snip-
That's because you haven't changed the Owner trust Thomas Voegtlin setting on the GPG Keychain.
Here I try to provide a guide:

The next process: verifying Electrum and its Signatures


MusaMohamed
Sr. Member
****
Offline Offline

Activity: 896
Merit: 290



View Profile
November 10, 2020, 03:17:50 AM
 #5

Verifications (with signature and documents).

On Electrum.org website and its page for documentation https://electrum.org/#documentation, they emphasize there are official documentation and unofficial guide:
Quote
Documentation
    Official documentation: electrum.readthedocs.io
    Unofficial guide: bitcoinelectrum.com

Bitzuma.com and that article is unofficial guide: https://bitzuma.com/posts/how-to-verify-an-electrum-download-on-mac/. It was updated on Updated November 28th, 2017 (3 years ago) and Electrum wallet released its new version 4.0.4.

If you get technical troubles with Electrum wallet, you can create topic in Electrum board.



R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBITCRYPTO
FUTURES
[
1,000x
LEVERAGE
][
.
COMPETITIVE
FEES
][
INSTANT
EXECUTION
]██████
██
██
██
██
██
██
██
██
██
██
██
██████
████████████████████████████████████████████████████████
.
TRADE NOW
.
████████████████████████████████████████████████████████
██████
██
██
██
██
██
██
██
██
██
██
██
██████
Husna QA
Legendary
*
Offline Offline

Activity: 2268
Merit: 2863


#SWGT CERTIK Audited


View Profile WWW
November 10, 2020, 06:05:41 AM
 #6

Verifications (with signature and documents).

On Electrum.org website and its page for documentation https://electrum.org/#documentation, they emphasize there are official documentation and unofficial guide:
Quote
Documentation
    Official documentation: electrum.readthedocs.io
    Unofficial guide: bitcoinelectrum.com

Bitzuma.com and that article is unofficial guide: https://bitzuma.com/posts/how-to-verify-an-electrum-download-on-mac/. It was updated on Updated November 28th, 2017 (3 years ago) and Electrum wallet released its new version 4.0.4.

If you get technical troubles with Electrum wallet, you can create topic in Electrum board.
I see that the tutorial on bitzuma.com is still relevant even the Thomas Voegtlin Key ID (0x2bd5824b7f9470e6) is still the same as the one here: https://electrum.readthedocs.io/en/latest/gpg-check.html (6694 D8DE 7BE8 EE56 31BE  D950 2BD5 824B 7F94 70E6);
Just replace the sample Electrum installer and signature with the latest Electrum installer and signature.

By the way, the documents at electrum.readthedocs.io, especially, in this case, https://electrum.readthedocs.io/en/latest/gpg-check.html, are also old documents. If you click the Edit on GitHub link in the top right corner, you will find https://github.com/spesmilo/electrum-docs/blob/master/gpg-check.rst (Latest commit dc454e4 on Apr 11, 2019).

odolvlobo
Legendary
*
Offline Offline

Activity: 4298
Merit: 3214



View Profile
November 10, 2020, 11:22:59 PM
Merited by ABCbits (1)
 #7

-snip-
When I attempt to verify signature of the electrum dmg file, it says 'untrusted file' 'signature not to be trusted'

Ive tried many times, downloading the files form electrum.org, reinstalling thomas v's key in GPG, but always the same response when i try to verify.
-snip-
That's because you haven't changed the Owner trust Thomas Voegtlin setting on the GPG Keychain.
Here I try to provide a guide:
...
After import the key, double-click the Thomas Voegtlin key. In the Owner Trust column, select Full or Ultimate:


Set the trust to Full. Ultimate is only for your own keys. Full is for other keys that have been proven to you.

Trust level explanation: https://gpgtools.tenderapp.com/kb/faq/what-is-ownertrust-trust-levels-explained

Join an anti-signature campaign: Click ignore on the members of signature campaigns.
PGP Fingerprint: 6B6BC26599EC24EF7E29A405EAF050539D0B2925 Signing address: 13GAVJo8YaAuenj6keiEykwxWUZ7jMoSLt
cr256 (OP)
Newbie
*
Offline Offline

Activity: 3
Merit: 5


View Profile
November 10, 2020, 11:41:23 PM
Merited by Husna QA (1)
 #8

Hi again.

I seem to have done it, thanks to everyone who helped.


From here: https://github.com/spesmilo/electrum-docs/blob/master/gpg-check.rst

Verify GPG signature

Run the following command from the same directory you saved the files replacing <electrum file> with the one actually downloaded:

gpg --verify <electrum file>.asc <electrum file>
The message should say:

Good signature from "Thomas Voegtlin (https://electrum.org) <thomasv@electrum.org>
and

Primary key fingerprint: 6694 D8DE 7BE8 EE56 31BE  D950 2BD5 824B 7F94 70E6
You can ignore this:

WARNING: This key is not certified with a trusted signature!
gpg:          There is no indication that the signature belongs to the owner.
as it simply means you have not established a web of trust with other GPG users





I did as it said, using terminal, and the response was:



$ gpg --verify electrum-4.0.4.dmg.asc electrum-4.0.4.dmg
gpg: Signature made Fri 16 Oct 05:21:39 2020 AEDT
gpg:                using RSA key 6694D8DE7BE8EE5631BED9502BD5824B7F9470E6
gpg: Good signature from "Thomas Voegtlin (https://electrum.org) <thomasv@electrum.org>" [unknown]
gpg:                 aka "ThomasV <thomasv1@gmx.de>" [unknown]
gpg:                 aka "Thomas Voegtlin <thomasv1@gmx.de>" [unknown]
gpg: WARNING: This key is not certified with a trusted signature!
gpg:          There is no indication that the signature belongs to the owner.


So I take that as it is a trusted signature.

Thanks again. Hope this thread helps someone else having trouble.

Husna QA
Legendary
*
Offline Offline

Activity: 2268
Merit: 2863


#SWGT CERTIK Audited


View Profile WWW
November 11, 2020, 01:09:20 AM
 #9

Set the trust to Full. Ultimate is only for your own keys. Full is for other keys that have been proven to you.

Trust level explanation: https://gpgtools.tenderapp.com/kb/faq/what-is-ownertrust-trust-levels-explained
Thank you for the additional information; Previously, I also suggested another option to set Ownertrust to Full.

Even without changing the settings on Ownertrust, it doesn't matter as long as the Electrum Application matches the original signature of the Electrum developer (Good signature from "Thomas Voegtlin (https://electrum.org) <thomasv@electrum.org>).

You can ignore this:

Code:
WARNING: This key is not certified with a trusted signature!
gpg:          There is no indication that the signature belongs to the owner.

as it simply means you have not established a web of trust with other GPG users

Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!