Re: sha512sum-error at debian-live-11.5.0-amd64-gnome.iso

Cyril Brulebois <[email protected]>
Newsgroups gmane.linux.debian.devel.cd
Organization Debian
Message-ID <[email protected]>
Hallo Gerd,

Please set something like LC_ALL=C, not everybody understands German. :)

Gerd Mühlenbruch <[email protected]> (2022-10-03):
> Today I downloaded the present debian-live-11.5.0-amd64-gnome.iso via my
> prepared script
> *********
> Optionen="-c -nv --show-progress --limit-rate=800k -a Ziele.log"
> Pfad="https://cdimage.debian.org/debian-cd/current-live/amd64/iso-hybrid"
> wget $Optionen $Pfad/debian-live-11.5.0-amd64-gnome.iso
> wget $Optionen $Pfad/debian-live-11.5.0-amd64-gnome.log
> wget $Optionen $Pfad/debian-live-11.5.0-amd64-gnome.packages
> rm SHA512SUMS
> rm SHA512SUMS.sign
> wget $Optionen $Pfad/SHA512SUMS
> wget $Optionen $Pfad/SHA512SUMS.sign
> *********
> 
> The final check
>     sha512sum --ignore-missing -c SHA512SUMS
> resulted into
>     debian-live-11.5.0-amd64-gnome.iso: FEHLSCHLAG
>     debian-live-11.5.0-amd64-gnome.log: OK
>     debian-live-11.5.0-amd64-gnome.packages: OK
>     sha512sum: WARNUNG: 1 berechnete Prüfsumme passte NICHT
> It was my first failed check.

I downloaded the same ISO, and SHA{256,512}SUMS with Firefox, and both
validate.

For the record, that's what I'm seeing:

    3efed2698da7fab0218a505eb504410d4cd9c7bc09478483bdbb3c593013b371  debian-live-11.5.0-amd64-gnome.iso
    450d09f1f1556effce4bc072ad395e45652aa40ed035b8ab35616c54fbef0c6edf803acb483ac25737b12bbae858277c1aa261eee36c4edf505a85c915d73c67  debian-live-11.5.0-amd64-gnome.iso

> Already since some years, the check
>     gpg --keyserver keyring.debian.org --verify SHA512SUMS.sign SHA512SUMS
> reports that the key doesn't have a trusted signature
>     gpg: Signatur vom So 11 Sep 2022 01:00:38 CEST
>     gpg:                mittels RSA-Schlüssel
> DF9B9C49EAA9298432589D76DA87E80D6294BE9B
>     gpg: Korrekte Signatur von "Debian CD signing key
> <[email protected]>" [unbekannt]
>     gpg: WARNUNG: Dieser Schlüssel trägt keine vertrauenswürdige Signatur!
>     gpg:          Es gibt keinen Hinweis, daß die Signatur wirklich dem
> vorgeblichen Besitzer gehört.
>     Haupt-Fingerabdruck  = DF9B 9C49 EAA9 2984 3258  9D76 DA87 E80D 6294
> BE9B
> This may be my own problem, because I haven't got a book to learn gpg.

The English version:

    $ gpg --keyserver keyring.debian.org --verify SHA512SUMS.sign SHA512SUMS
    gpg: Signature made Sun 11 Sep 2022 01:00:38 CEST
    gpg:                using RSA key DF9B9C49EAA9298432589D76DA87E80D6294BE9B
    gpg: Good signature from "Debian CD signing key <[email protected]>" [unknown]
    gpg: WARNING: This key is not certified with a trusted signature!
    gpg:          There is no indication that the signature belongs to the owner.
    Primary key fingerprint: DF9B 9C49 EAA9 2984 3258  9D76 DA87 E80D 6294 BE9B

The important part is that the signature is correct. The warning is
about your not having set a level of trust for the signing key. That's
not a problem.


Cheers,
-- 
Cyril Brulebois ([email protected])            <https://debamax.com/>
D-I release manager -- Release team member -- Freelance Consultant
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEEtg6/KYRFPHDXTPR4/5FK8MKzVSAFAmM6rmQACgkQ/5FK8MKz
VSCG0A//RvHaaMpJuV8GovfoijkN9fJEB5gkwXjP4l7YKEefrB+6rK+heiJe06i2
eDktBvXHA6E+Q7HZ8J1EZZSkwyQItx8DY4kakC9F+LGxEP09J7J7+AAVsG/+w4IY
sUdl6tD3Hf41dOo2Dg/Ly2SatkEmftE0B9/Wdnn0DlMWDQPGtOCbj/AwVPrJ2i3q
MPUrqfMgTlW6sCTpOj8BxiJKIxmac2iD2HWnHunWUAKjiFuvl9VvwwxZTNOTgmNZ
Cf3sHeoWtnfsvbo6q1ropa4L/ijPrmxjao8tncEMvcobCSWRisGyGqVT3Z/MmQdA
IYN76VdA7q9oRLnmCLk8BSfHv14kUonoX1ZI29USTkvslrP7m0ivCa6KRY/Z3MyW
ui8lWifICzX1CwxkueK1heGofvAJFjDbASPsRAZpMpZfWTvUOiRcRQkjv/WAYzCS
YZa0B0rurKPN3T8V6PvZOpdStMqLqiewqrc4+ekh7M4XorDZ4V+suUJcD8DJpiEp
/68xbcijtG3prN2iLI2f0hPxFGbM1ANIe7iQJPnuLurSjtgctgaHNjYDO6S3kxlz
4rTn5CFvIGtSmOyPIhrM5d8HG5gTF1FOHsDjxsEHLbKqNJtwBMt1NO3hJlOtr0ub
t+NSET+i/b0RQf1NRGU3fM6HCgHWrIzta672qtGbCZezt/jO4WU=
=xG9x
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.