[Bug 574184] Re: Bad signatures for 10.04 installer validation: MD5SUM SHA1SUM SHA256SUM

Reşat SABIQ tilde.birlik at gmail.com
Wed May 5 05:42:38 UTC 2010


Hi Jeremy,

thanks for at least getting back to me. However, i think you are on the
wrong track. Have you tried verifying a DVD iso signature (not a CD)? I
get the feeling that you haven't.

This is what i get on a new installation:
$ gpg --keyserver hkp://keyserver.ubuntu.com --recv-keys 0xFBB75451
gpg: requesting key FBB75451 from hkp server keyserver.ubuntu.com
gpg: key FBB75451: public key "Ubuntu CD Image Automatic Signing Key <cdimage at ubuntu.com>" imported
gpg: no ultimately trusted keys found
gpg: Total number processed: 1
gpg:               imported: 1
$ gpg --verify MD5SUMS.gpg MD5SUMS
gpg: Signature made Cum 30 Apr 2010 11:03:30 EEST using DSA key ID FBB75451
gpg: BAD signature from "Ubuntu CD Image Automatic Signing Key <cdimage at ubuntu.com>"
$ 

Verify these 2 please, and please post an update here whether you CAN or CAN'T verify them:
http://cdimage.ubuntu.com/releases/10.04/release/MD5SUMS.gpg
http://cdimage.ubuntu.com/releases/10.04/release/MD5SUMS

P.S. To make abs sure we are on the same track, this is the file i'm trying to verify:
http://cdimage.ubuntu.com/releases/10.04/release/ubuntu-10.04-dvd-i386.iso

Thanks.

** Changed in: linux (Ubuntu)
       Status: Incomplete => Confirmed

** Tags removed: needs-upstream-testing

-- 
Bad signatures for 10.04 installer validation: MD5SUM SHA1SUM SHA256SUM
https://bugs.launchpad.net/bugs/574184
You received this bug notification because you are a member of Kernel
Bugs, which is subscribed to linux in ubuntu.




More information about the kernel-bugs mailing list