X-Git-Url: https://git.distorted.org.uk/~mdw/sgt/putty/blobdiff_plain/2285d016cf0103f03e05e53e22025282c104a164..5462f4596108c4309fb69b4e57aa1e59d7100908:/doc/pgpkeys.but diff --git a/doc/pgpkeys.but b/doc/pgpkeys.but index b3d104d9..cdb0e938 100644 --- a/doc/pgpkeys.but +++ b/doc/pgpkeys.but @@ -4,7 +4,7 @@ \cfg{winhelp-topic}{pgpfingerprints} -We create \i{PGP signatures} for all the PuTTY +\I{verifying new versions}We create \i{PGP signatures} for all the PuTTY files distributed from our web site, so that users can be confident that the files have not been tampered with. Here we identify our public keys, and explain our signature policy so you can have an @@ -12,13 +12,11 @@ accurate idea of what each signature guarantees. This description is provided as both a web page on the PuTTY site, and an appendix in the PuTTY manual. -As of the next release, all of the PuTTY executables will contain -\#{XXX-REMOVE-BEFORE-RELEASE: fix this up for forthcoming release -As of release 0.58, all of the PuTTY executables contain} -fingerprint material (usually accessed via the \i\c{-pgpfp} -command-line option), such that if you have an executable you trust, -you can use it to establish a trust path, for instance to a newer -version downloaded from the Internet. +As of release 0.58, all of the PuTTY executables contain fingerprint +material (usually accessed via the \i\c{-pgpfp} command-line +option), such that if you have an executable you trust, you can use +it to establish a trust path, for instance to a newer version +downloaded from the Internet. (Note that none of the keys, signatures, etc mentioned here have anything to do with keys used with SSH - they are purely for verifying @@ -42,39 +40,25 @@ they sign it in return. Therefore, we have six public keys in total: \b RSA: +\W{http://www.chiark.greenend.org.uk/~sgtatham/putty/keys/master-rsa.asc}{Master Key}, +\W{http://www.chiark.greenend.org.uk/~sgtatham/putty/keys/release-rsa.asc}{Release key}, +\W{http://www.chiark.greenend.org.uk/~sgtatham/putty/keys/snapshot-rsa.asc}{Snapshot key} \lcont{ - -\b \W{http://www.chiark.greenend.org.uk/~sgtatham/putty/keys/master-rsa.asc}{Master Key} - -\lcont{ -1024-bit; fingerprint: +Master Key: 1024-bit; \I{PGP key fingerprint}fingerprint: \cw{8F\_15\_97\_DA\_25\_30\_AB\_0D\_\_88\_D1\_92\_54\_11\_CF\_0C\_4C} } -\b \W{http://www.chiark.greenend.org.uk/~sgtatham/putty/keys/release-rsa.asc}{Release key} - -\b \W{http://www.chiark.greenend.org.uk/~sgtatham/putty/keys/snapshot-rsa.asc}{Snapshot key} - -} - \b DSA: +\W{http://www.chiark.greenend.org.uk/~sgtatham/putty/keys/master-dsa.asc}{Master Key}, +\W{http://www.chiark.greenend.org.uk/~sgtatham/putty/keys/release-dsa.asc}{Release key}, +\W{http://www.chiark.greenend.org.uk/~sgtatham/putty/keys/snapshot-dsa.asc}{Snapshot key} \lcont{ - -\b \W{http://www.chiark.greenend.org.uk/~sgtatham/putty/keys/master-dsa.asc}{Master Key} - -\lcont{ -1024-bit; fingerprint: +Master Key: 1024-bit; fingerprint: \cw{313C\_3E76\_4B74\_C2C5\_F2AE\_\_83A8\_4F5E\_6DF5\_6A93\_B34E} } -\b \W{http://www.chiark.greenend.org.uk/~sgtatham/putty/keys/release-dsa.asc}{Release key} - -\b \W{http://www.chiark.greenend.org.uk/~sgtatham/putty/keys/snapshot-dsa.asc}{Snapshot key} - -} - \H{pgpkeys-security} Security details The various keys have various different security levels. This