Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.security > #6227
| From | Jonathan Wiltshire <jmw@debian.org> |
|---|---|
| Newsgroups | linux.debian.security |
| Subject | Re: timestamp of the signature of Debian 12 netinst |
| Date | 2023-06-23 19:10 +0200 |
| Message-ID | <GJSsh-nuY-1@gated-at.bofh.it> (permalink) |
| References | <GJQqt-lPn-7@gated-at.bofh.it> <GJQqt-lPn-9@gated-at.bofh.it> <GJQqt-lPn-11@gated-at.bofh.it> <GJQqt-lPn-13@gated-at.bofh.it> <GJQqt-lPn-5@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
On 23 June 2023 15:53:08 BST, Julian Schreck <js-priv@online.de> wrote: >Dear all, >I was downloading the netimage of bookworm, the signing key(s) and sha sums when I noticed that my timestamp of the signature [0] differs from the one on the website. [1] >Is this a security issue or just a website not updated? > >Kind regards >Julian >-- >[0] : >$ LC_ALL=C gpg --verify-files SHA512SUMS.sign >gpg: assuming signed data in 'SHA512SUMS' >gpg: Signature made Sat Jun 10 15:58:35 2023 CEST >gpg: using RSA key DF9B9C49EAA9298432589D76DA87E80D6294BE9B >gpg: Good signature from "Debian CD signing key <debian-cd@lists.debian.org>" [unknown] >gpg: WARNING: This key is not certified with a trusted signature! >gpg: There is no indication that the signature belongs to the owner. >Primary key fingerprint: DF9B 9C49 EAA9 2984 3258 9D76 DA87 E80D 6294 BE9B > >[1] : https://www.debian.org/CD/verify, e. g. 2011-01-05 [SC] > You're comparing the timestamp of a signature with the creation time of the key which generated it. They're different things. -- Jonathan Wiltshire jmw@debian.org Debian Developer http://people.debian.org/~jmw 4096R: 0xD3524C51 / 0A55 B7C5 1223 3942 86EC 74C3 5394 479D D352 4C51
Back to linux.debian.security | Previous | Next — Previous in thread | Find similar
timestamp of the signature of Debian 12 netinst Julian Schreck <js-priv@online.de> - 2023-06-23 17:00 +0200
Re: timestamp of the signature of Debian 12 netinst "Adam D. Barratt" <adam@adam-barratt.org.uk> - 2023-06-23 18:20 +0200
Re: timestamp of the signature of Debian 12 netinst Julian Schreck <js-priv@online.de> - 2023-06-23 21:00 +0200
Re: timestamp of the signature of Debian 12 netinst Jeremy Stanley <fungi@yuggoth.org> - 2023-06-23 22:20 +0200
Re: timestamp of the signature of Debian 12 netinst Jonathan Wiltshire <jmw@debian.org> - 2023-06-24 20:30 +0200
Re: timestamp of the signature of Debian 12 netinst Julian Schreck <js-priv@online.de> - 2023-06-24 20:30 +0200
Re: timestamp of the signature of Debian 12 netinst Jonathan Wiltshire <jmw@debian.org> - 2023-06-23 19:10 +0200
csiph-web