Security issue: deprecated 32-bit key ID is recommended for verification of the Linux Mint ISO
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 35/100
- Issue type
- Documentation
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- linux
- Domain
- documentation, security
Research direction
Start in the Linux Mint Installation Guide at Verify your ISO image → Authenticity check, then review the commands and key identifier shown in the issue. Update the guidance to avoid recommending a 32-bit key ID and ensure the verification example uses the full identifier; check the corresponding language guides mentioned in the report for the same wording.
Written by the indexing model from the issue text.
Description
I checked English and several other language guides and found out that OpenPGP 32-bit key ID is recommended as an alternative for verifying an ISO.
Linux Mint Installation Guide --> Verify your ISO image --> Authenticity check
If gpg complains about the key ID, try the following commands instead:
gpg --keyserver hkp://keyserver.ubuntu.com:80 --recv-key A25BAE09
gpg --list-key --with-fingerprint A25BAE09
Check the output of the last command, to make sure the fingerprint is 27DE B156 44C6 B3CF 3BD7 D291 300F 846B A25B AE09 (with or without spaces).
results in
pub rsa1024 2014-01-26 [C]
1828 C98D 1C52 E20C 95DF B632 6ABA 455A A25B AE09
uid [ unknown] Totally Legit Signing Key <[email protected]>
There are some users in the wild including Linux Mint forum which are not familiar enough with GnuPG to resolve a problem even if they see that signature is wrong. It is a well known issue and only full 64-bit identifiers should be used. See:
https://github.com/jwilk/stopgp32
https://seclists.org/oss-sec/2018/q3/174
- Dominant language
- No language data
- Stars
- 52
- Forks
- 36
- PR merge metrics
- No merged PRs in 30d
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from linuxmint/doc-user-guide
-
Explicit white backgrounds for QR codesPossibly taken @whoa220 claimed this 89 days ago. Open
Difficulty 2/5 1-3 hours Newbie friendliness 62/100
linuxmint/doc-user-guide#15 · 3 comments ·
-
explain `netdev`(VPN, Bluetooth) and other permissionsPossibly taken @whoa220 claimed this 113 days ago. Open
Difficulty 3/5 1-2 days Newbie friendliness 45/100
linuxmint/doc-user-guide#42 · 1 comment ·
-
Difficulty 4/5 3-5 days Newbie friendliness 35/100
linuxmint/doc-user-guide#41 ·
-
Difficulty 4/5 3-5 days Newbie friendliness 15/100
linuxmint/doc-user-guide#39 · 2 comments ·
-
Difficulty 5/5 Over a week Newbie friendliness 20/100
linuxmint/doc-user-guide#31 ·
All issues in linuxmint/doc-user-guide
Similar issues
-
documentation good first issue
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
-
good first issue
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
-
Difficulty 1/5 1-3 hours Newbie friendliness 70/100
Maintainers usually reply within 1 day
-
documentation
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
AR-js-org/arjs-plugin-artoolkit#70 ·
Maintainers usually reply within 1 day
-
documentation good first issue help wanted
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
Maintainers usually reply within 1 day