Return-Path: X-Original-To: apmail-pdfbox-users-archive@www.apache.org Delivered-To: apmail-pdfbox-users-archive@www.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id BA0AF11933 for ; Sun, 20 Jul 2014 17:37:45 +0000 (UTC) Received: (qmail 95538 invoked by uid 500); 20 Jul 2014 17:37:45 -0000 Delivered-To: apmail-pdfbox-users-archive@pdfbox.apache.org Received: (qmail 95515 invoked by uid 500); 20 Jul 2014 17:37:45 -0000 Mailing-List: contact users-help@pdfbox.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: users@pdfbox.apache.org Delivered-To: mailing list users@pdfbox.apache.org Received: (qmail 95465 invoked by uid 99); 20 Jul 2014 17:37:44 -0000 Received: from nike.apache.org (HELO nike.apache.org) (192.87.106.230) by apache.org (qpsmtpd/0.29) with ESMTP; Sun, 20 Jul 2014 17:37:44 +0000 X-ASF-Spam-Status: No, hits=0.7 required=5.0 tests=RCVD_IN_DNSWL_NONE,SPF_NEUTRAL X-Spam-Check-By: apache.org Received-SPF: neutral (nike.apache.org: local policy) Received: from [81.169.146.161] (HELO mo4-p00-ob.smtp.rzone.de) (81.169.146.161) by apache.org (qpsmtpd/0.29) with ESMTP; Sun, 20 Jul 2014 17:37:42 +0000 DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; t=1405877837; l=4857; s=domk; d=lehmi.de; h=Content-Transfer-Encoding:Content-Type:In-Reply-To:References: Subject:To:MIME-Version:From:Date; bh=fN+GvDFP/uzb0/divRJYia0oJEo=; b=t5/ITZGhAFGhMiBvEDu2wS4TNjEhYP6eT5Hqr+J+ujc2wrPcAbrU88aWk5zkqPOpi7+ 8kw8+LBSIsfsC1D9SCJXnzyGd8RqgHtXszG+nvcihdtZmzffHzQuFlDMwMiyJnYE3svEw dEhUV9ldoK0hWc8rFyK21hJJxrVu0rUZdP0= X-RZG-AUTH: :LWIAZ0WpaN8UY5o8XRz0jOyrHsdEC+nAE10OdySrgHvHRPUZnJ9uQPREtAsi X-RZG-CLASS-ID: mo00 Received: from [10.195.1.6] ([178.162.205.2]) by smtp.strato.de (RZmta 35.2 AUTH) with ESMTPSA id 606432q6KHbHPTn (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) for ; Sun, 20 Jul 2014 19:37:17 +0200 (CEST) Message-ID: <53CBFE4C.4030103@lehmi.de> Date: Sun, 20 Jul 2014 19:37:16 +0200 From: Andreas Lehmkuehler User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Thunderbird/24.6.0 MIME-Version: 1.0 To: users@pdfbox.apache.org Subject: Re: BAD SIGNATUREs on pdfbox/fontbox downloads References: <006801cf9ac5$cca146b0$65e3d410$@correlationconcepts.com> <208390AE-7C2F-4F78-8F54-EECB1B0381D8@fileaffairs.de> <006701cf9b9e$219d78e0$64d86aa0$@correlationconcepts.com> In-Reply-To: <006701cf9b9e$219d78e0$64d86aa0$@correlationconcepts.com> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 8bit X-Virus-Checked: Checked by ClamAV on apache.org Hi, Am 09.07.2014 19:49, schrieb Mark Bobick, CTO: > Maruan, > > If I'm sticking with PGP/GPG, then the only thing to do is import the key > from the MIT server and see what happens. > > This is what happened: > > [developer3@bf19650mdfl Downloads]$ ls pdfbox* > -rw-r--r--. 1 developer3 developer3 33476 Jul 8 11:13 pdfbox-1.8.6.jar The downloaded jar file is corrupt, it is way to small. It's size has to be 4mb and not just 33kb. Please change the mirrow and/or check your method downloading the file. BR Andreas Lehmk�hler > -rw-r--r--. 1 developer3 developer3 181 Jul 8 11:13 pdfbox-1.8.6.jar.asc > [developer3@bf19650mdfl Downloads]$ sudo gpg pdfbox-1.8.6.jar.asc > [sudo] password for developer3: > gpg: Signature made Thu 19 Jun 2014 07:57:08 AM EDT using DSA key ID > 1DFDBF44 > gpg: BAD signature from "Andreas Lehmkuehler (CODE SIGNING KEY) > " > [developer3@bf19650mdfl Downloads]$ sudo gpg --keyserver pgpkeys.mit.edu > --recv-key 1DFDBF44 > gpg: requesting key 1DFDBF44 from hkp server pgpkeys.mit.edu > gpg: key 1DFDBF44: "Andreas Lehmkuehler (CODE SIGNING KEY) > " not changed > gpg: Total number processed: 1 > gpg: unchanged: 1 > [developer3@bf19650mdfl Downloads]$ sudo gpg pdfbox-1.8.6.jar.asc > gpg: Signature made Thu 19 Jun 2014 07:57:08 AM EDT using DSA key ID > 1DFDBF44 > gpg: BAD signature from "Andreas Lehmkuehler (CODE SIGNING KEY) > " > [developer3@bf19650mdfl Downloads]$ sudo gpg --fingerprint 1DFDBF44 > pub 1024D/1DFDBF44 2009-03-26 > Key fingerprint = A602 970F E1BF 5C9C 8A94 91B9 7A3C 9FE2 1DFD BF44 > uid Andreas Lehmkuehler (CODE SIGNING KEY) > > sub 2048g/78CB2E94 2009-03-26 > [developer3@bf19650mdfl Downloads]$ > > Have downloaded both jar and asc files several times with same result. > Would prefer to resolve issue, but I'll run checksums as alternative, and > will advise if anything off. Thanks for the follow-up. > > Regards, > > -mark bobick > > -----Original Message----- > From: Maruan Sahyoun [mailto:sahyoun@fileaffairs.de] > Sent: Wednesday, July 09, 2014 1:24 PM > To: users@pdfbox.apache.org > Subject: Re: BAD SIGNATUREs on pdfbox/fontbox downloads > > Dear Mark, > > I did try the verification on OSX Maverick and Fedora 20 wo any issues. Is > it possible to use a different system to verify that you still get the same > error? > > BR > Maruan Sahyoun > > Am 08.07.2014 um 18:00 schrieb Mark Bobick, CTO > : > >> Downloaded KEYS and PDFBOX and FONTBOX files from >> https://pdfbox.apache.org/downloads.html. >> >> OS: Linux Fedora 20 (Heisenbug) >> >> >> >> This is outcome from posted on same page "Verify" protocol. Please >> advise my error or other, and recommended action. >> >> >> >> [developer3@bf19650mdfl ~]$ cd Downloads [developer3@bf19650mdfl >> Downloads]$ ls KEYS -rw-r--r--. 1 developer3 developer3 11822 Jul 8 >> 11:15 KEYS [developer3@bf19650mdfl Downloads]$ ls pdfbox* -rw-r--r--. >> 1 developer3 developer3 33476 Jul 8 11:13 pdfbox-1.8.6.jar >> -rw-r--r--. 1 developer3 developer3 181 Jul 8 11:13 > pdfbox-1.8.6.jar.asc >> [developer3@bf19650mdfl Downloads]$ ls fontbox* -rw-r--r--. 1 >> developer3 developer3 33596 Jul 8 11:14 fontbox-1.8.6.jar >> -rw-r--r--. 1 developer3 developer3 181 Jul 8 11:14 > fontbox-1.8.6.jar.asc >> [developer3@bf19650mdfl Downloads]$ gpg --import KEYS >> gpg: key A355A63E: public key "Jukka Zitting " >> imported >> gpg: key 8A26D9A6: public key "Jukka Zitting " >> imported >> gpg: key 1DFDBF44: public key "Andreas Lehmkuehler (CODE SIGNING KEY) >> " imported >> gpg: Total number processed: 3 >> gpg: imported: 3 >> gpg: no ultimately trusted keys found >> [developer3@bf19650mdfl Downloads]$ sudo gpg --verify >> pdfbox-1.8.6.jar.asc [sudo] password for developer3: >> gpg: Signature made Thu 19 Jun 2014 07:57:08 AM EDT using DSA key ID >> 1DFDBF44 >> gpg: BAD signature from "Andreas Lehmkuehler (CODE SIGNING KEY) >> " >> [developer3@bf19650mdfl Downloads]$ sudo gpg --verify >> fontbox-1.8.6.jar.asc >> gpg: Signature made Thu 19 Jun 2014 07:54:19 AM EDT using DSA key ID >> 1DFDBF44 >> gpg: BAD signature from "Andreas Lehmkuehler (CODE SIGNING KEY) >> " >> [developer3@bf19650mdfl Downloads]$ >> >> >> >> Thanks & Regards, >> >> >> >> -mark bobick >> LinkedIn >> >> >> >> CTO, Correlation Concepts >> >> www.correlationconcepts.com >> >> 2880 David Walker Dr. #407 >> >> Eustis, Florida 32726 >> >> 702.882.5664 >> >> >> >> "We will find a way, or we will make one." - Hannibal >> >> >> > >