Overhauls intro and code signing section. Adds hint about SHA-256
SignTool: Link MSDN docs where to get it.
|Deletions are marked like this.||Additions are marked like this.|
|Line 24:||Line 24:|
|A third way verify the integrity is, to open open a command line, navigate to the folder and enter||A third way is to use
which is a part of the Microsoft development tools:
Open open a command line, navigate to the folder and enter
Check integrity of Gpg4win packages
You shall only run applications on your computer that you trust. This page shows several methods to check that the software called Gpg4win that you have just downloaded originates from the Gpg4win Initiative.
Code Signing Certificate
All Gg4win installer files since April 2016 are code signed. The signature informations used to code sign the packages can be found on the Gpg4Win package integrity site. Windows can check the integrity and the publisher of a signed software package.
Method A: UAC
When trying to run the installer on Windows, the User Access Control dialog will show the publisher, check that is the one you expected it to be. :) (If you have disabled User Access Control use a different method.)
Method B: file properties
A second way is to use the file properties in the explorer. Right click on the installer -> properties -> digital signatures -> Details of signatures. Use this with Firefox or Iridium (Chromium) until T3379 is solved.
Method C: signtool
A third way is to use MSDN:SignTool which is a part of the Microsoft development tools: Open open a command line, navigate to the folder and enter
SignTool verify gpg4win*.exe
Once you downloaded the file from Gpg4Win.org, you can verify its SHA1 checksums. On machines that run Windows 8 or newer, you can receive the desired output, by opening a command line, navigate to your Download-Folder and put in the line:
certutil -hashfile FileToHash.exe sha1
On Systems that run older operating systems, than Windows 8: Install a certain Windows Patch, which delivers the functionality.
Once you entered the operation, the command line will return an alphanumeric string, which yyou can compare to the one on the Gpg4Win package integrity site.
(These instructions are written for SHA-1 and not the stronger SHA-256 because we are not aware of standard Microsoft tools to check SHA-256 for elder versions of Windows. If you have a tool to check SHA-256, use it instead.)
If you upgrade your Gpg4Win version, you already have gnupg installed and you can verify the integrity of the downloaded file, by its OpenPGP signature. To do so, you have to download, next the file, the signature of the file. You'll find the download-links on the Gpg4Win package integrity site. The Key, with which the files are signed, is also given on that page. You have to import the key and now you can validate the signature of the file with the command
gpg --verify gpg4win*.exe.sig gpg4win*.exe
Navigate to the folder, where you downloaded the Gpg4Win packages to, and enter
The command will list all files and their sizes in the directory. You can then compare those results with the sizes given on the Gpg4Win package integrity site.
If you encounter any problems, please feel free to ask them at the forums or on the mailinglist. If you already figured out, how to fix your issue, please leave your answer here