Bitcoin Forum
May 11, 2024, 06:51:26 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: Verifying Electrum - 3 valid signatures?  (Read 123 times)
dustyrose1510 (OP)
Newbie
*
Offline Offline

Activity: 2
Merit: 11


View Profile
February 26, 2022, 08:31:20 AM
Merited by AB de Royse777 (5), o_e_l_e_o (4), ABCbits (2)
 #1

Hello everyone. I was hoping someone could clarify for me why I am getting this message as I'm unsure if it's safe to continue with my electrum download?
Is it normal to have 3 valid signatures?

I have finished the process of verifying electrum using Kleopatra. I used the appropriate file on Kleopatra (downloaded directly from Electrum's official website): ThomasV.asc   

When I click verify on "electrum--4.15-setup.exe.asc" I receive the following message (the top of the message says "All operations completed" with a thick green line) :



Verified ‘electrum-4.1.5-setup.exe’ with ‘electrum-4.1.5-setup.exe.asc’: 3 valid signatures.

Signature created on Thursday, 22 July 2021 10:49:18 PM
With unavailable certificate:
ID: 0x637DB1E23370F84AFF88CCE03152347D07DA627C
You can search the certificate on a keyserver or import it from a file.

Signature created on Tuesday, 20 July 2021 5:20:06 AM
With unavailable certificate:
ID: 0x0EEDCFD5CAFB459067349B23CA9EEEC43DF911DC
You can search the certificate on a keyserver or import it from a file.

Signature created on Tuesday, 20 July 2021 4:22:28 AM
With certificate:
Thomas Voegtlin (https://electrum.org) <thomasv@electrum.org> (2BD5 824B 7F94 70E6)
The signature is valid and the certificate's validity is fully trusted.

1715453486
Hero Member
*
Offline Offline

Posts: 1715453486

View Profile Personal Message (Offline)

Ignore
1715453486
Reply with quote  #2

1715453486
Report to moderator
1715453486
Hero Member
*
Offline Offline

Posts: 1715453486

View Profile Personal Message (Offline)

Ignore
1715453486
Reply with quote  #2

1715453486
Report to moderator
1715453486
Hero Member
*
Offline Offline

Posts: 1715453486

View Profile Personal Message (Offline)

Ignore
1715453486
Reply with quote  #2

1715453486
Report to moderator
You can see the statistics of your reports to moderators on the "Report to moderator" pages.
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715453486
Hero Member
*
Offline Offline

Posts: 1715453486

View Profile Personal Message (Offline)

Ignore
1715453486
Reply with quote  #2

1715453486
Report to moderator
1715453486
Hero Member
*
Offline Offline

Posts: 1715453486

View Profile Personal Message (Offline)

Ignore
1715453486
Reply with quote  #2

1715453486
Report to moderator
nc50lc
Legendary
*
Offline Offline

Activity: 2408
Merit: 5595


Self-proclaimed Genius


View Profile
February 26, 2022, 08:46:58 AM
Merited by o_e_l_e_o (4), pooya87 (2), ABCbits (2), hosseinimr93 (1)
 #2

That's because the newer binaries are now signed by three developers: ThomasV, SomberNight and Emzy.
It's mentioned in the download page: https://electrum.org/#download

You may obtain the other two devs' GPG Key, links in the download page or in Github repo: https://github.com/spesmilo/electrum/tree/master/pubkeys

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
o_e_l_e_o
In memoriam
Legendary
*
Offline Offline

Activity: 2268
Merit: 18512


View Profile
February 26, 2022, 11:02:36 AM
Last edit: February 26, 2022, 11:18:44 AM by o_e_l_e_o
Merited by hosseinimr93 (1)
 #3

The first two are telling you the signatures are valid, but it doesn't know whether it can trust the keys which provided those valid signatures since you have not imported those keys in to Kleopatra. The last signature is both valid and trusted since you have imported ThomasV's key.

As nc50lc has said, you can import the other two keys if you want to be triple sure that you have the legitimate file.

I can also confirm that 0x0EEDCFD5CAFB459067349B23CA9EEEC43DF911DC matches the key I have for SomberNight and 0x637DB1E23370F84AFF88CCE03152347D07DA627C matches the signing key I have for Emzy (Stephan Oeste).
dustyrose1510 (OP)
Newbie
*
Offline Offline

Activity: 2
Merit: 11


View Profile
February 27, 2022, 02:03:11 AM
 #4

I just tried to import the other two keys from the official Electrum website. SomberNight was successful but I am unsure about Emzy (Stephan Oeste) because the key/fingerprint is very different to my original message & the key you just gave me.

This is the fingerprint I get when looking at the Emzy file in Kleopatra:

9EDA FF80 E080 6596 04F4 A76B 2EBB 056F D847 F8A7


Is it safe to certify this?

Thank you so much for your assistance!
nc50lc
Legendary
*
Offline Offline

Activity: 2408
Merit: 5595


Self-proclaimed Genius


View Profile
February 27, 2022, 02:23:39 AM
Merited by dustyrose1510 (2)
 #5

This is the fingerprint I get when looking at the Emzy file in Kleopatra:

9EDA FF80 E080 6596 04F4 A76B 2EBB 056F D847 F8A7
It matches the fingerprint of Emzy' GPG key that I've imported: 9EDA FF80 E080 6596 04F4 A76B 2EBB 056F D847 F8A7
Both public keys from the download page and the repository matches that fingerprint.

Sombernight's is the same as the one in o_e_l_e_o 's reply.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
o_e_l_e_o
In memoriam
Legendary
*
Offline Offline

Activity: 2268
Merit: 18512


View Profile
February 27, 2022, 09:00:42 AM
Merited by dustyrose1510 (2)
 #6

This is the fingerprint I get when looking at the Emzy file in Kleopatra:

9EDA FF80 E080 6596 04F4 A76B 2EBB 056F D847 F8A7


Is it safe to certify this?
Yes, it is safe.

Emzy uses a number of subkeys within that key. The key fingerprint I have for Emzy is also 9EDA FF80 E080 6596 04F4  A76B 2EBB 056F D847 F8A7.

If you double click on that key in Kleopatra, and then click on "More details...", you should see his signing key with the ID 3152 347D 07DA 627C. This is the key I quoted above and the key which matches the signature your Kleopatra verified in your first post.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!