Menu

How to use .sig file?

Help
2004-10-18
2012-09-17
  • Frank Denman

    Frank Denman - 2004-10-18

    In the downloads list, along with pwsafe-2.06-bin.zip, I see pwsafe-2.06-bin.zip.sig, which I suppose is likely a hash used to verify the zip file.

    How would I use the sig file to verify the zip file?

    Thanks.

    Frank

     
    • Rony Shapiro

      Rony Shapiro - 2004-10-20

      Hi,

      You're right in that the .sig file is like a hash, in that it can be used to verify the integrity of the binary zip file. In addition, the sig file can assure you that the hash was generated by the signer - in this case, me.

      To verify the signature, you need to get PGP (http://www.pgp.com/downloads/index.html - last time I checked, free for personal use) or it's GNU equivalent, gpg (http://www.gnupg.org/ - no usage restrictions). Once you've installed one of those, you'll need my public key, available from http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xFA175557

      Rony

       
    • Alex Fung

      Alex Fung - 2005-01-27

      Rony, I think you should publish your fingerprint somewhere, so that we can verify the trust the public key.

       
      • Rony Shapiro

        Rony Shapiro - 2005-01-28

        Good idea. I've added the fingerprint to the link to the key on the project homepage (http://passwordsafe.sourceforge.net/).

        Cheers,

        Rony
        
         
        • todd ricker

          todd ricker - 2008-01-29

          i don't see the public key anymore on the site. and unfortuneately MIT's pks server is not responding.

          thanks.

          --todd

           

Log in to post a comment.