
Since the RSAs match we get the message saying "Good signature. So as far as i can see, it gets the public key 7F2D434B9741E8AC because of the auto-key-retrieve and then checks the RSA key (primary key fingerprint) against the decoded (with the public key) version from the. Gpg: There is no indication that the signature belongs to the owner. Gpg: WARNING: This key is not certified with a trusted signature! Gpg: Good signature from "Pierre Schmitz "

Gpg: key 7F2D434B9741E8AC: public key "Pierre Schmitz " imported Gpg: requesting key 7F2D434B9741E8AC from hkp server Gpg4win is a handy, free (gpl) Windows software, b. To be more sure you downloaded the right key you can type “GnuPG.exe -fingerprint F379A1C6” and it should return “1DC3 C8C4 316A 698A C494 039C F5B8 4436 F379 A1C6”.ĮDIT: Changed angle brackets to square brackets since the forum software didn’t show what was written inside.Schnell% gpg -keyserver-options auto-key-retrieve -verify archlinux-2020.11.01-x86_64.iso.sig Gpg4win latest version: A Free (GPL) Security program for Windows. Then that is ok, it just means you haven’t sign Manfred’s key with your own. If it returns that it is a good signature, but that there is no indication the key belongs to the owner or something like that.


I have never used windows for this, but I am going to try and predict how it is used, so it is very possible it won’t work, but hopefully you will figure it out.
