We person published Qubes Security Bulletin (QSB) 118: Dom0 arbitrary codification execution successful qvm-copy-to-vm correction reporting. The matter of this QSB and its accompanying cryptographic signatures are reproduced below, followed by a wide mentation of this announcement and authentication instructions.
Qubes Security Bulletin 118
Source: qsb-118-2026.txt
Marek Marczykowski-Górecki’s PGP signature
Source: qsb-118-2026.txt.sig.marmarek
Simon Gaiser (aka HW42)’s PGP signature
Source: qsb-118-2026.txt.sig.simon
What is the intent of this announcement?
The intent of this announcement is to pass the Qubes organization that a caller Qubes information bulletin (QSB) has been published.
What is simply a Qubes information bulletin (QSB)?
A Qubes information bulletin (QSB) is simply a information announcement issued by the Qubes information team. A QSB typically provides a summary and effect study of 1 aliases much recently-discovered package vulnerabilities, including specifications astir patching to reside them.
Why should I attraction astir QSBs?
QSBs show you what actions you must return successful bid to protect yourself from recently-discovered information vulnerabilities. In astir cases, information vulnerabilities are addressed by updating normally. However, successful immoderate cases, typical personification action is required. In each cases, the required actions are elaborate successful QSBs.
What are the PGP signatures that travel QSBs?
A PGP signature is simply a cryptographic digital signature made successful accordance pinch the OpenPGP standard. PGP signatures tin beryllium cryptographically verified pinch programs for illustration GNU Privacy Guard (GPG). The Qubes information squad cryptographically signs each QSBs truthful that Qubes users person a reliable measurement to cheque whether QSBs are genuine. The only measurement to beryllium definite that a QSB is authentic is by verifying its PGP signatures.
Why should I attraction whether a QSB is authentic?
A forged QSB could deceive you into taking actions that adversely impact the information of your Qubes OS system, specified arsenic installing malware aliases making configuration changes that render your strategy susceptible to attack. Falsified QSBs could sow fear, uncertainty, and uncertainty astir the information of Qubes OS aliases the position of the Qubes OS Project.
How do I verify the PGP signatures connected a QSB?
The pursuing command-line instructions presume a Linux strategy pinch git and gpg installed. (For Windows and Mac options, spot OpenPGP software.)
-
Obtain the Qubes Master Signing Key (QMSK), e.g.:
$ gpg --fetch-keys https://keys.qubes-os.org/keys/qubes-master-signing-key.asc gpg: directory '/home/user/.gnupg' created gpg: keybox '/home/user/.gnupg/pubring.kbx' created gpg: requesting cardinal from 'https://keys.qubes-os.org/keys/qubes-master-signing-key.asc' gpg: /home/user/.gnupg/trustdb.gpg: trustdb created gpg: cardinal DDFA1A3E36879494: nationalist cardinal "Qubes Master Signing Key" imported gpg: Total number processed: 1 gpg: imported: 1(For much ways to get the QMSK, spot How to import and authenticate the Qubes Master Signing Key.)
-
View the fingerprint of the PGP cardinal you conscionable imported. (Note: gpg> indicates a punctual wrong of the GnuPG program. Type what appears aft it erstwhile prompted.)
$ gpg --edit-key 0x427F11FD0FAA4B080123F01CDDFA1A3E36879494 gpg (GnuPG) 2.2.27; Copyright (C) 2021Software Foundation, Inc. This is free software: you are free to alteration and redistribute it. There is NO WARRANTY, to the grade permitted by law. pub rsa4096/DDFA1A3E36879494 created: 2010-04-01 expires: ne'er usage: SC trust: chartless validity: unknown [ unknown] (1). Qubes Master Signing Key gpg> fpr pub rsa4096/DDFA1A3E36879494 2010-04-01 Qubes Master Signing Key Primary cardinal fingerprint: 427F 11FD 0FAA 4B08 0123 F01C DDFA 1A3E 3687 9494 -
Important: At this point, you still don’t cognize whether the cardinal you conscionable imported is the genuine QMSK aliases a forgery. In bid for this full process to supply meaningful information benefits, you must authenticate the QMSK out-of-band. Do not skip this step! The modular method is to get the QMSK fingerprint from multiple independent sources successful respective different ways and cheque to spot whether they lucifer the cardinal you conscionable imported. For much information, spot How to import and authenticate the Qubes Master Signing Key.
Tip: After you person authenticated the QMSK out-of-band to your satisfaction, grounds the QMSK fingerprint successful a safe spot (or several) truthful that you don’t person to repetition this measurement successful the future.
-
Once you are satisfied that you person the genuine QMSK, group its spot level to 5 (“ultimate”), past discontinue GnuPG pinch q.
gpg> trust pub rsa4096/DDFA1A3E36879494 created: 2010-04-01 expires: ne'er usage: SC trust: chartless validity: unknown [ unknown] (1). Qubes Master Signing Key Please determine really acold you spot this personification to correctly verify different users' keys (by looking astatine passports, checking fingerprints from different sources, etc.) 1 = I don't cognize aliases won't say 2 = I do NOT trust 3 = I spot marginally 4 = I spot fully 5 = I spot ultimately m = backmost to the main menu Your decision? 5 Do you really want to group this cardinal to eventual trust? (y/N) y pub rsa4096/DDFA1A3E36879494 created: 2010-04-01 expires: ne'er usage: SC trust: eventual validity: unknown [ unknown] (1). Qubes Master Signing Key Please statement that the shown cardinal validity is not needfully correct unless you restart the program. gpg> q -
Use Git to clone the qubes-secpack repo.
$ git clone https://github.com/QubesOS/qubes-secpack.git Cloning into 'qubes-secpack'... remote: Enumerating objects: 4065, done. remote: Counting objects: 100% (1474/1474), done. remote: Compressing objects: 100% (742/742), done. remote: Total 4065 (delta 743), reused 1413 (delta 731), pack-reused 2591 Receiving objects: 100% (4065/4065), 1.64 MiB | 2.53 MiB/s, done. Resolving deltas: 100% (1910/1910), done. -
Import the included PGP keys. (See our PGP cardinal policies for important accusation astir these keys.)
$ gpg --import qubes-secpack/keys/*/* gpg: cardinal 063938BA42CFA724: nationalist cardinal "Marek Marczykowski-Górecki (Qubes OS signing key)" imported gpg: qubes-secpack/keys/core-devs/retired: publication error: Is a directory gpg: nary valid OpenPGP information found. gpg: cardinal 8C05216CE09C093C: 1 signature not checked owed to a missing key gpg: cardinal 8C05216CE09C093C: nationalist cardinal "HW42 (Qubes Signing Key)" imported gpg: cardinal DA0434BC706E1FCF: nationalist cardinal "Simon Gaiser (Qubes OS signing key)" imported gpg: cardinal 8CE137352A019A17: 2 signatures not checked owed to missing keys gpg: cardinal 8CE137352A019A17: nationalist cardinal "Andrew David Wong (Qubes Documentation Signing Key)" imported gpg: cardinal AAA743B42FBC07A9: nationalist cardinal "Brennan Novak (Qubes Website & Documentation Signing)" imported gpg: cardinal B6A0BB95CA74A5C3: nationalist cardinal "Joanna Rutkowska (Qubes Documentation Signing Key)" imported gpg: cardinal F32894BE9684938A: nationalist cardinal "Marek Marczykowski-Górecki (Qubes Documentation Signing Key)" imported gpg: cardinal 6E7A27B909DAFB92: nationalist cardinal "Hakisho Nukama (Qubes Documentation Signing Key)" imported gpg: cardinal 485C7504F27D0A72: 1 signature not checked owed to a missing key gpg: cardinal 485C7504F27D0A72: nationalist cardinal "Sven Semmler (Qubes Documentation Signing Key)" imported gpg: cardinal BB52274595B71262: nationalist cardinal "unman (Qubes Documentation Signing Key)" imported gpg: cardinal DC2F3678D272F2A8: 1 signature not checked owed to a missing key gpg: cardinal DC2F3678D272F2A8: nationalist cardinal "Wojtek Porczyk (Qubes OS archiving signing key)" imported gpg: cardinal FD64F4F9E9720C4D: 1 signature not checked owed to a missing key gpg: cardinal FD64F4F9E9720C4D: nationalist cardinal "Zrubi (Qubes Documentation Signing Key)" imported gpg: cardinal DDFA1A3E36879494: "Qubes Master Signing Key" not changed gpg: cardinal 1848792F9E2795E9: nationalist cardinal "Qubes OS Release 4 Signing Key" imported gpg: qubes-secpack/keys/release-keys/retired: publication error: Is a directory gpg: nary valid OpenPGP information found. gpg: cardinal D655A4F21830E06A: nationalist cardinal "Marek Marczykowski-Górecki (Qubes information pack)" imported gpg: cardinal ACC2602F3F48CB21: nationalist cardinal "Qubes OS Security Team" imported gpg: qubes-secpack/keys/security-team/retired: publication error: Is a directory gpg: nary valid OpenPGP information found. gpg: cardinal 4AC18DE1112E1490: nationalist cardinal "Simon Gaiser (Qubes Security Pack signing key)" imported gpg: Total number processed: 17 gpg: imported: 16 gpg: unchanged: 1 gpg: marginals needed: 3 completes needed: 1 spot model: pgp gpg: depth: 0 valid: 1 signed: 6 trust: 0-, 0q, 0n, 0m, 0f, 1u gpg: depth: 1 valid: 6 signed: 0 trust: 6-, 0q, 0n, 0m, 0f, 0u -
Verify signed Git tags.
$ cd qubes-secpack/ $ git tag -v `git describe` object 266e14a6fae57c9a91362c9ac784d3a891f4d351 type commit tag marmarek_sec_266e14a6 tagger Marek Marczykowski-Górecki 1677757924 +0100 Tag for perpetrate 266e14a6fae57c9a91362c9ac784d3a891f4d351 gpg: Signature made Thu 02 Mar 2023 03:52:04 AM PST gpg: utilizing RSA cardinal 2D1771FE4D767EDC76B089FAD655A4F21830E06A gpg: Good signature from "Marek Marczykowski-Górecki (Qubes information pack)" [full]The nonstop output will differ, but the last statement should ever commencement pinch gpg: Good signature from... followed by an due key. The [full] indicates afloat trust, which this cardinal inherits successful kindness of being validly signed by the QMSK.
-
Verify PGP signatures, e.g.:
$ cd QSBs/ $ gpg --verify qsb-087-2022.txt.sig.marmarek qsb-087-2022.txt gpg: Signature made Wed 23 Nov 2022 04:05:51 AM PST gpg: utilizing RSA cardinal 2D1771FE4D767EDC76B089FAD655A4F21830E06A gpg: Good signature from "Marek Marczykowski-Górecki (Qubes information pack)" [full] $ gpg --verify qsb-087-2022.txt.sig.simon qsb-087-2022.txt gpg: Signature made Wed 23 Nov 2022 03:50:42 AM PST gpg: utilizing RSA cardinal EA18E7F040C41DDAEFE9AA0F4AC18DE1112E1490 gpg: Good signature from "Simon Gaiser (Qubes Security Pack signing key)" [full] $ cd ../canaries/ $ gpg --verify canary-034-2023.txt.sig.marmarek canary-034-2023.txt gpg: Signature made Thu 02 Mar 2023 03:51:48 AM PST gpg: utilizing RSA cardinal 2D1771FE4D767EDC76B089FAD655A4F21830E06A gpg: Good signature from "Marek Marczykowski-Górecki (Qubes information pack)" [full] $ gpg --verify canary-034-2023.txt.sig.simon canary-034-2023.txt gpg: Signature made Thu 02 Mar 2023 01:47:52 AM PST gpg: utilizing RSA cardinal EA18E7F040C41DDAEFE9AA0F4AC18DE1112E1490 gpg: Good signature from "Simon Gaiser (Qubes Security Pack signing key)" [full]Again, the nonstop output will differ, but the last statement of output from each gpg --verify bid should ever commencement pinch gpg: Good signature from... followed by an due key.
For this announcement (QSB-118), the commands are:
You tin besides verify the signatures straight from this announcement successful summation to aliases alternatively of verifying the files from the qubes-secpack. Simply transcript and paste the QSB-118 matter into a plain matter record and do the aforesaid for some signature files. Then, execute the aforesaid authentication steps arsenic listed above, substituting the filenames supra pinch the names of the files you conscionable created.
English (US) ·
Indonesian (ID) ·