Integrity checking with GPG

AddThis Social Bookmark Button

Signing keys plays an important role in the development and distribution of pilot-link. Not only does it help you verify that the files you download from this website were actually created by me,
it also ensures that they were never tampered with or modified in-transit.

GnuPG stands for "GNU Privacy Guard" and, like PGP, is primarily used to provide electronic privacy. Both GnuPG and PGP make it possible for individuals to send private messages over the Internet -- messages that are private because they are encrypted. This encryption works by using public key encryption for encoding the private messages at one end of the connection and decoding them at the other.

Public key encryption always involves the use of two keys -- one private and never revealed by its owner, the other public and shared without concern. These keys are created in a single operation and are intimately related. You can think of them as opposites: one undoes what the other does. When a message is encrypted with one of the keys, it can only be decrypted with the other. This makes it possible for someone to encrypt a message that can only be decrypted by the intended recipient. It also makes it possible for someone to decrypt a message and know that it can only have been encrypted by one individual. Depending on how it is used, therefore, public key encryption gives us privacy or sender authentication -- as long as private keys remain private.

For more info about GPG, check out the GPG Home Page.

This is my GPG public key. Please use it for anything you might send me, or to verify any current or future pilot-link releases.

This key is also available on various keyservers, such as this one.

-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1.4.6 (GNU/Linux)

mQGiBDriqY4RBAC7Ts13TGDuGXwZ5vLv1kqBrv6c8CBB5ORs71/yhvrAA/BPoFbt
M66ekvnXjRFjfw/57X+U13MSQDqqi97W3Fe1frh4414bkg4n52mq4KY/CUW0PzhC
CL6PQC26GsBr02NTPdIIqtiW3HUVOW+GR3IFmu+GnatrTVUai+A3bt5rUwCg45Zf
EYNRQJAYKkrsuCeHwhejtTsD/igeS9a7juGp9kZ/iu4Fhx/F2mo43GwGsx8sEDRu
CNxv5AKJeFbGgxAlITCfID/xnn/Wpryh0AjLb88rbDcrU3+4aEFwysADXz5q/Kzt
yCyn/5uwnNNBJdgqUSSnmEhw/7HFOk7wBeQbaNMsBTXEcl/aG0Fbt4D5Be9Fz/vm
HKtMA/0eFJZ4ic598fJs/IEpUqvhwwoa7a2E9aAzSeAJ8mL7g30i5A+k18mx4CFB
ZEDDZNiSYWiszrY8pHnNEe0NjgrovkiMbXeZ6a9g2KizKjKotJNEUV+95k17CbGJ
6B3Ou9CYTsSMgs4/NHaM4+6DM5vh+ymTFkwT22vrFiGSEk5hrrQmRGF2aWQgQS4g
RGVzcm9zaWVycyA8c2V0dWlkQGdtYWlsLmNvbT6IYAQTEQIAIAUCRbscigIbAwYL
CQgHAwIEFQIIAwQWAgMBAh4BAheAAAoJEJEUBEZwda5KphYAoIw3AH2Od965mOxQ
FgJOE3uZe8LdAJoD31Um5+Uq2aeTvRpENqvhycJWKbQsRGF2aWQgQS4gRGVzcm9z
aWVycyA8ZGVzcm9kQGdudS1kZXNpZ25zLmNvbT6IYwQTEQIAIwIbAwYLCQgHAwIE
FQIIAwQWAgMBAh4BAheABQJFux0SAhkBAAoJEJEUBEZwda5Ktt0AnjvNISWVpgoO
FSGdUcW8VF8061a6AJ9Jjt9zcko6FQ9aqHGGUlpjomXWl7RCRGF2aWQgQS4gRGVz
cm9zaWVycyAoZ3BnIERTQSBhbmQgRWxHYW1hbCkgPGhhY2tlckBnbnUtZGVzaWdu
cy5jb20+iFwEExECABwFAj3RWWgCGwMECwcDAgMVAgMDFgIBAh4BAheAAAoJEJEU
BEZwda5K2WAAoLRarf+XSprp4Ij8Ypq2CsUILSH4AJ9TJVqBtPBNpzKa25hsMIAp
HfPXFIhGBBIRAgAGBQI99jkmAAoJENGVGa1MfyvuL+YAoKUSBkO2AnwckOFDs2gV
B12IUTA9AJ9hamfu36w7YgQH3ws29AH33jH/uYhGBBARAgAGBQI65fT9AAoJEJcW
sik7qjrgkKgAn0Vbmv4cuTKFGqiKn/HYIGl+SYTCAJ0Qxx4dsS28XInivi+DXUMN
F1aoiIhXBBMRAgAXBQI64qmOBQsHCgMEAxUDAgMWAgECF4AACgkQkRQERnB1rkoN
YACgrY4mcpRszLIhsiUlBZqLINdEaYsAoLxCAPBzITm5q+n0gczf2UbeD8yWiEYE
EBECAAYFAj00b/MACgkQcB9D6GCw1E4xCgCg65kfWP3z85Q0yolZUrPXJc8xnhYA
oLmD2+rzqugEXIcUqu6nwKb76stwiEYEEhECAAYFAj32OSIACgkQ0ZUZrUx/K+4x
pACfcX44Ua97BgZfNLA76TZ3gCXvFIAAoIgc08qJxp9u/+1oT9Sc4NmSmH5UuQEN
BDriqZMQBAD1ch54DCnHiQeBJyq3GjonddFK6zkIDGF/DFk6+1LhiynPPxvIzKrZ
KvLCtD7NcNUqtnlKQmZOKMgowQovOjN5FGBX5SGYPmHMUKqxGfRiJgarBmXDItaD
gH+uKvjrcmmrEGMAQ37V6Zp0o9IguX/S39XxSpj1Z9VT8CXUsvPXywADBQQAlJSX
mpYZKD1pZRwhkfXwRlAMC0qZCg26QwRO5AuHQCUMzS77FlK80jxVD362Ec12qWzz
ru8pJDjuu6S8F3e8iBHx5aQAkWrfvYeWbsVc/nVB56mvlb2pwBySL+gtho98BbVR
KEOJvJ/HcpGls8j6xGHZxNS5KDYp5m0uArZCzPOIRgQYEQIABgUCOuKpkwAKCRCR
FARGcHWuSiHgAKC4qb+oDGxZqmQyKpyLFUvko60omwCfdX36c4c4sxakLGKw9XMv
L+Kawg4=
=vddC
-----END PGP PUBLIC KEY BLOCK-----

Key fingerprint = 125A 3A28 0F57 72F7 AF7B 67DF 9114 0446 7075 AE4A

To import this key into your own keyring, simply save the key below to a plain text file (such as one called 'keys.asc', for an "ASCII" key file), and invoke the following command:

gpg --import key.asc

Alternately, if your browser supports the MIME type of application/pgp-keys, you can click here to import it directly.

You can add this support directly into your ~/.mailcap file (which your browser reads), by adding or editing the following line:

application/pgp-keys; gpg --import < %s | more; needsterminal

If you know me (and can verify that this key came from me), please sign my key and mail
me
a copy of the signature, so I can add you to my public keyring.

To verify a release of pilot-link with this key, download the tarball of pilot-link and the associated .sig, .asc, or .gpg key that it was signed with, and execute the following command:

gpg --verify pilot-link-1.0.tar.gz.asc pilot-link-1.0.tar.gz

By verifying a file with a digital signature, you verify the source of the file. In other words, you can be certain that the file came from me, packaged by me, and was not tampered in any way by any third-parties.

Please don't forget to upload your key to the nearest PGP/GPG keyserver, after signing, so that the Web of Trust is extended and strengthened.

Thanks again for your continued support of the pilot-link project.