Size: 2727
Comment: Complete Rework in same structure
|
Size: 4172
Comment: fix typo, update file property method hint towards T3379, add that UAC is the recommend method, And using one method is good enough. Better indication of file length section.
|
Deletions are marked like this. | Additions are marked like this. |
Line 1: | Line 1: |
= Check integrity of Gpg4win packages = You can check packages by their SHA1 Checksum, by OpenPGP Singature (if you already have GnuPG installed) or by the Code Signing Certficate. The Checksums and Information you need to verify your downloaded package files, are available on the [[https://www.gpg4win.org/package-integrity.html|Gpg4Win package integrity]] site. |
= Check integrity of Gpg4win packages You shall only run applications on your computer that you trust. This page shows several methods to check that the software called Gpg4win that you have just downloaded originates from the Gpg4win Initiative. Using one is good enough. |
Line 6: | Line 10: |
== SHA1 checksums == | == Code Signing Certificate All Gpg4win installer files since April 2016 are code signed. The signature informations used to code sign the packages can be found on the [[https://www.gpg4win.org/package-integrity.html|Gpg4Win package integrity]] site. Windows can check the integrity and the publisher of a signed software package. |
Line 8: | Line 14: |
Once you downloaded the file from [[https://www.gpg4win.org/|Gpg4Win.org]], you can verify its SHA1 checksums. On machines that run Windows 8 or newer, you can recieve the desired output, by opening a command line, navigate to your Download-Folder and put in the line: | ==== Method A: UAC (recommended) When trying to run the installer on Windows, the **User Access Control dialog will show the publisher**, check that it is the one you expected it to be. :) (If you have disabled User Access Control use a different method.) |
Line 10: | Line 19: |
{{{certutil -hashfile FileToHash.exe sha1}}} | ==== Method B: file properties A second way is to use the file properties in the explorer. Right click on the installer -> properties -> digital signatures -> Details of signatures. (Try this if no publisher is shown by the UAC in rare cases after a download with Firefox or Iridium (Chromium). For details see [[https://dev.gnupg.org/T3379|T3379]].) |
Line 12: | Line 24: |
On Systems that run older operating systems, then Windows 8: Install a certain [[https://support.microsoft.com/en-us/kb/934576?spid=12925&sid=1569|Windows Patch]], wich delivers the functionality. | ==== Method C: signtool A third way is to use [[https://msdn.microsoft.com/en-us/library/windows/desktop/aa387764(v=vs.85).aspx|MSDN:SignTool]] which is a part of the Microsoft development tools: Open open a command line, navigate to the folder and enter |
Line 14: | Line 30: |
Once you entered the operation, the command line will return an alphanumeric string, which yu can compare to the one on the [[https://www.gpg4win.org/package-integrity.html|Gpg4Win package integrity]] site. | {{{SignTool verify gpg4win*.exe}}} == Checksums Once you have downloaded the file, you can verify that it matches the published checksums (that you have gotten via a trusted channel). Open a command line, navigate to your Download-Folder and put in the line: {{{certutil -hashfile gpg4win-3.1.7.exe sha256}}} If this does not work, try {{{sha1}}} instead of {{{sha256}}}. (SHA-256 is to be preferred, but we are not aware of a standard Microsoft tool to check SHA-256 for elder versions of Windows. If you have a different tool available to check SHA-256 checksums, you can use it.) On systems that run older operating systems than Windows 8: Install a certain [[https://support.microsoft.com/en-us/kb/934576?spid=12925&sid=1569|Windows Patch]], which delivers the functionality. Once you have entered the command, it will return an alphanumeric string, which you can compare to the one on the [[https://www.gpg4win.org/package-integrity.html|Gpg4Win package integrity]] site. Make sure to compare it to the checksum with the same algorithm (SHA-256 or SHA-1). |
Line 22: | Line 54: |
== File lengths == | == File lengths (as diagnostics) This is not a verification method, but I way trying to find out why a method my have failed. One cause of a bad download is that the internet connection broke down during the download. In this case the size of the file on your harddisk is smaller than it should be. |
Line 29: | Line 65: |
== Code Signing Certificate == | This can help you spot a corrupt file where the downloading got aborted or something. It will not protect you against an attacker. |
Line 31: | Line 68: |
All Gg4win installer files since April 2016 that can be downloaded via [[https://www.gpg4win.org/|Gpg4Win.org]] are code signed. The signature informations used to code sing the packages can be found on the [[https://www.gpg4win.org/package-integrity.html|Gpg4Win package integrity]] site. To verify the integrity, you open a command line, navigate to the folder and enter {{{SignTool verify gpg4win*.exe}}} |
Check integrity of Gpg4win packages
You shall only run applications on your computer that you trust. This page shows several methods to check that the software called Gpg4win that you have just downloaded originates from the Gpg4win Initiative. Using one is good enough.
Contents
Code Signing Certificate
All Gpg4win installer files since April 2016 are code signed. The signature informations used to code sign the packages can be found on the Gpg4Win package integrity site. Windows can check the integrity and the publisher of a signed software package.
Method A: UAC (recommended)
When trying to run the installer on Windows, the User Access Control dialog will show the publisher, check that it is the one you expected it to be. :) (If you have disabled User Access Control use a different method.)
Method B: file properties
A second way is to use the file properties in the explorer. Right click on the installer -> properties -> digital signatures -> Details of signatures. (Try this if no publisher is shown by the UAC in rare cases after a download with Firefox or Iridium (Chromium). For details see T3379.)
Method C: signtool
A third way is to use MSDN:SignTool which is a part of the Microsoft development tools: Open open a command line, navigate to the folder and enter
SignTool verify gpg4win*.exe
Checksums
Once you have downloaded the file, you can verify that it matches the published checksums (that you have gotten via a trusted channel). Open a command line, navigate to your Download-Folder and put in the line:
certutil -hashfile gpg4win-3.1.7.exe sha256
If this does not work, try sha1 instead of sha256. (SHA-256 is to be preferred, but we are not aware of a standard Microsoft tool to check SHA-256 for elder versions of Windows. If you have a different tool available to check SHA-256 checksums, you can use it.)
On systems that run older operating systems than Windows 8: Install a certain Windows Patch, which delivers the functionality.
Once you have entered the command, it will return an alphanumeric string, which you can compare to the one on the Gpg4Win package integrity site. Make sure to compare it to the checksum with the same algorithm (SHA-256 or SHA-1).
OpenPGP signatures
If you upgrade your Gpg4Win version, you already have gnupg installed and you can verify the integrity of the downloaded file, by its OpenPGP signature. To do so, you have to download, next the file, the signature of the file. You'll find the download-links on the Gpg4Win package integrity site. The Key, with which the files are signed, is also given on that page. You have to import the key and now you can validate the signature of the file with the command
gpg --verify gpg4win*.exe.sig gpg4win*.exe
File lengths (as diagnostics)
This is not a verification method, but I way trying to find out why a method my have failed. One cause of a bad download is that the internet connection broke down during the download. In this case the size of the file on your harddisk is smaller than it should be.
Navigate to the folder, where you downloaded the Gpg4Win packages to, and enter
dir
The command will list all files and their sizes in the directory. You can then compare those results with the sizes given on the Gpg4Win package integrity site.
This can help you spot a corrupt file where the downloading got aborted or something. It will not protect you against an attacker.
Troubleshooting
If you encounter any problems, please feel free to ask them at the forums or on the mailinglist. If you already figured out, how to fix your issue, please leave your answer here