Can someone help me understand how to verify a pgp signature?

I’m on Ubuntu 24.04 LTS

Ok I’m trying to verify this whonix ova, so this is where I downloaded the whonix ova https://www.whonix.org/wiki/VirtualBox so like I said I’ve already downloaded the whonix ova but now I’d like to verify it.

Ok so I took a screenshot of it

Can someone please just walk me through this?

And I did google “how to verify pgp on ubuntu” and honestly there aren’t too many tutorials that pop up, well I checked out this tutorial here https://www.linuxbabe.com/security/verify-pgp-signature-software-downloads-linux and I started reading it and she says “On the VeraCrypt download page, you can also find the PGP public key and PGP signature download link. Click the links to download these two files.” So wait a second, so I need to download both the PGP public key and PGP signature?

I’m confused, can someone help me understand pgp keys and what to do?

So yeah I’ve already downloaded the whonix ova and now I’d like to verify it before I install it but I’ve never done pgp keys before so I need to learn how to do it. Thank you.

Yeah and the tutorials on pgp keys on Ubuntu on the internet are lacking, there aren’t that many of them. Like really only a few pop up on google. And I know the verification of the whonix ova is optional but I’d still like to finally learn how to do pgp keys cause I’ve never done it before. Yeah I’ve known about pgp keys for years and so I’d like to learn how to do them.

Edit: Make sure you check out her tutorial, at one point she says there is a published fingerprint on the veracrypt website that you have to compare to, but I can’t find a fingerprint on the whonix website. I’m confused.

Edit: So look at this screenshot please

you see she says “Compare it with the fingerprint published on VeraCrypt website.”

Yeah I can’t find a published fingerprint anywhere on the whonix website. I need an expert to explain this to me?

I can’t find the fingerprint on the whonix website.

Yeah I’m totally stumped, I don’t know how to do this.

Maybe I just didn’t read it but did you follow the link Verify_the_image at the bottom of your first screenshot? And from there you may follow Linux (Section OpenPGP Signature / Virtualbox).

1 Like

How come in this tutorial https://www.linuxbabe.com/security/verify-pgp-signature-software-downloads-linux she says “Compare it with the fingerprint published on VeraCrypt website.” Please take the time and check out the tutorial, you’ll see what I’m talking about. Or just look at the screenshot I took above.

How come there is a published fingerprint on the veracrypt website that you must compare to but not on the whonix website? I’m just trying to wrap my head around this.

How to verify the signature of a Whonix image from the Whonix website seems like a great question for Whonix support.

As we don’t provide Whonix support on Ubuntu Discourse, closing.