Signing keys¶
Dangerzone uses several keys to sign what it ships. This page lists them so that you can cross-check fingerprints from more than one place.
Release key (PGP)¶
Our binaries, source archives, container archives, and checksums are signed with a PGP key owned by Freedom of the Press Foundation.
| Name | Dangerzone Release Key |
[email protected] |
|
| Fingerprint | DE28 AB24 1FA4 8260 FAC9 B8BA A7C9 B385 2260 4281 |
| Signing subkey | 04CA BEB5 DD76 BACF 2BD4 3D2F F3AC C60F 62EA 51CB |
| Download | keys.openpgp.org |
The same key signs the APT and RPM repositories at packages.freedom.press, which is why the fingerprint above is the one to confirm when dnf asks Importing GPG key 0x22604281.
Cross-check the fingerprint with the footer of dangerzone.rocks and the bio of our Mastodon account. How to use it: Verify PGP signatures.
Sandbox image key (Cosign)¶
The sandbox container image is signed with Cosign. The public key is shipped with every Dangerzone installation as share/freedomofpress-dangerzone.pub, next to a detached PGP signature of it (freedomofpress-dangerzone.pub.asc) made with the release key above. Dangerzone verifies every sandbox image against this key before using it. See Independent sandbox updates.
Signatures are recorded in the Sigstore transparency log (Rekor). Dangerzone bundles and pins the Rekor public key as share/rekor.pub. It can be overridden with SIGSTORE_REKOR_PUBLIC_KEY, see environment variables.
Platform code signing¶
- macOS: the application bundle and
.dmgare signed with theDeveloper ID Application: Freedom of the Press Foundation (94ZZGGGJ3W)certificate and notarized by Apple. - Windows:
dangerzone.exe,dangerzone-cli.exe, and the.msiinstaller are signed with a code-signing certificate owned by Freedom of the Press Foundation and provided by Azure Trusted Signing.
These signatures are checked by the operating system. The PGP signatures provide an independent, second check.