Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Problem Installation Check Signature #701

Closed
antidot18 opened this issue Feb 22, 2013 · 7 comments
Closed

Problem Installation Check Signature #701

antidot18 opened this issue Feb 22, 2013 · 7 comments

Comments

@antidot18
Copy link

@antidot18 antidot18 commented Feb 22, 2013

~]$ gpg --verify youtube-dl.sig /usr/local/bin/youtube-dl
gpg: Signature made Tue 19 Feb 2013 12:08:08 AM CET using DSA key ID FAFB085C
gpg: Can't check signature: public key not found

I have not idea how to proceed, sorry. I have not found the same problem in the others "Issues".

Thank you!

@phihag
Copy link
Contributor

@phihag phihag commented Feb 22, 2013

That's because you don't have my key downloaded and trusted. Import it from my homepage or a keyserver (with gpg --recv FAFB085C), and mark it as trusted (using the lsign command, or the corresponding function in a graphical interface). Of course, you should verify that it's really me (i.e. that the fingerprint matches).

@phihag phihag closed this Feb 22, 2013
@antidot18
Copy link
Author

@antidot18 antidot18 commented Feb 22, 2013

Thank you, but:

~]$ gpg --recv FAFB085C
gpg: requesting key FAFB085C from hkp server keys.gnupg.net
gpg: key FAFB085C: public key "Philipp Hagemeister phihag@phihag.de" imported
gpg: no ultimately trusted keys found
gpg: Total number processed: 1
gpg: imported: 1

[perfect thanks]

~]$ gpg --verify youtube-dl.sig /usr/local/bin/youtube-dl
gpg: Signature made Fri 22 Feb 2013 04:45:57 PM CET using DSA key ID FAFB085C
gpg: Good signature from "Philipp Hagemeister phihag@phihag.de"
gpg: aka "Philipp Hagemeister ubuntu@phihag.de"
gpg: WARNING: This key is not certified with a trusted signature!
gpg: There is no indication that the signature belongs to the owner.
Primary key fingerprint: 0600 E1DB 6FB5 3A5D 95D8 FC0D F5EA B582 FAFB 085C

[here I must trust it with "lsign" but I never listened about this command. Searching information I found: http://linux.about.com/library/cmd/blcmdl1_gpg.htm
But later some attemps I have not succeed.

I'm sorry, I have been trying multiple thing but without progress. It could be just me, but some other people could be not very acquainted with these commands too. It would be really nice if you may whrite them in http://rg3.github.com/youtube-dl/download.html]

Thank you!! ^^

@rg3
Copy link
Collaborator

@rg3 rg3 commented Feb 22, 2013

If you want to use gpg to verify signatures or for other purposes, the GNU Privacy Handbook is a good read.

http://www.gnupg.org/gph/en/manual.html

There is a section on the ring of trust and trusting keys.

http://www.gnupg.org/gph/en/manual.html#AEN335

@antidot18
Copy link
Author

@antidot18 antidot18 commented Feb 23, 2013

Sorry, my question is:
¿How I "mark it as trusted"? Just this command line in console.

Like:
~]$ gpg --edit-key trust youtube-dl.sig <---- But the correct one. [I did different attempts]

Thanks.

@phihag
Copy link
Contributor

@phihag phihag commented Feb 23, 2013

gpg --lsign-key FAFB085C

should work just fine.

@antidot18
Copy link
Author

@antidot18 antidot18 commented Feb 24, 2013

Thank you very much!!!

I needed create my key too!! Thank you and sorry for inconvenience.

May be you will be agree to add few new lines in: http://rg3.github.com/youtube-dl/download.html Because I wanted this program for the Edx courses.
As problably you know, Edx courses (online courses of MIT, Berkley...) use this program as part of their script, as you can see here:
https://github.com/shk3/edx-downloader

I didn't know something about gpg (and probably a lot of future/new users too); whith just these new lines in http://rg3.github.com/youtube-dl/download.html a lot of problems can be prevented:

gpg --gen-key <--- And follow instructions (new gpg users)
gpg --recv FAFB085C <--- (May be add alternatives too)
gpg --lsign-key FAFB085C

Thank you very much again and good work with these programs!! ;D

@phihag
Copy link
Contributor

@phihag phihag commented Feb 24, 2013

@antidot18 gpg is just used to verify that the download worked out alright (in the near future, I'll see to it that we use SSL as well), it is not actually needed to download youtube-dl.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
3 participants
You can’t perform that action at this time.