this post was submitted on 21 Jan 2024
1 points (100.0% liked)

Sysadmin

12 readers
1 users here now

A reddit dedicated to the profession of Computer System Administration.

founded 2 years ago
MODERATORS
 
This is an automated archive.

The original was posted on /r/sysadmin by /u/TheCrazyPhoenix416 on 2024-01-21 18:15:53+00:00.


Question

I have two pgp public keys for the same company - one from their website, the other from the hockypuck keyserver.

These keys are different! ๐Ÿ˜จ๐Ÿ˜ฑ

Though, at least, the session encryption modulus (n) and exponent (e) are the same.

How do I verify if either key is trustworthy?

Details

I was browsing through IVPN's website and came across their warrant canary report with a link to their pgp public key to download. The question is, how can I verify the public key I download is trustworthy.

I downloaded this key from their website, and found the same pgp public key on the hockypuck keyservers. If they match, the key is probably trustworthy, but they aren't the same.

I've looked through the pgp key packets (using ), and they're mostly the same. The RSA session encryption keys (i.e. modulus n and exponent e) are the same. However, they have mismatched signature packets (though most are the same too).

Can anyone explain what this means?

no comments (yet)
sorted by: hot top controversial new old
there doesn't seem to be anything here