GPG validation Key installation | Community
Skip to main content
Newcomer
October 11, 2022
Solved

GPG validation Key installation

  • October 11, 2022
  • 15 replies
  • 13 views

I just got notification to install a new GPG validation key. I tried what they suggested (VERY poor commands mixed with comments!!) and got nowhere. I am running ubuntu (latest stable version). Any and all help would be appreciated.

    Best answer by jmiahjones_ur

    Zoom published a support article. It sounds like more details will be coming soon.

    15 replies

    Newcomer
    October 11, 2022

    I'm in the same boat too. The email almost looked like a phishing attempt. There is no mention of GPG key rotation on your website.

    Newcomer
    October 11, 2022

    I received a message from "Zoom Video Communications <***********>" stating that they will be retiring the current key pair used to sign the Linux client on November 2, 2022, and gives the instructions referred to by adit47.

     

    I am somewhat reluctant to follow the instructions, given the many instances of phishing, and would request from this community assurance that this is legit!  I have not gone so far as to test the commands recommended so I cannot comment on their efficacy. 

     

    Thanks!

    Newcomer
    October 20, 2022

    The command suggested may work in Ubuntu but I am running Manjaro (which is based on Arch), so I have no idea how to proceed.

     

    Any Manjaro or Arch-based knowledgeable people out there who can help?

    Newcomer
    October 11, 2022

    Same here. The commands are a garbled mess, and neither one works. All I get is error messages when I run them. I am pretty sure that the email comes from zoom.us, so it's most likely legitimate, but I am at a complete loss as to what to do now.

     

    HEY ZOOM! Does this mean my Linux client will stop working on November 2, 2022? If so, then how in the world do I fix it? Uninstall, then re-install the client after November 2?

    Newcomer
    October 11, 2022

    I also received the e-mail and wonder if it was a scam too... it is so suspicious that it is not commented on the web...

    I would wait until it is announced there...   however it looks like the kind of instructions you would receive to install a new gpg key:

    ``` gpg --import ~/Downloads/package-signing-key.pub ```

    ``` dpkg-sig --verify ./zoom.deb ```

    Newcomer
    October 12, 2022

    I'm also concerned about the email I received resembling a phishing attempt. I can't find anything on the website referring to this. Please Zoom folks, publish something or give us a link.

    Newcomer
    October 12, 2022

    I think I can help. This appears legit..

    After you run gpg command, download the latest Ubuntu client from the download center:

    zoom_amd64.deb                     (or equivalent for your OS)

    run dpkg-sig --verify ./zoom_amd64.deb            (you may have to be in the /Downloads directory for this to work).

    You'll receive:

     

    GOODSIG _gpgbuilder XXXXXXXXXXXXXXXXXXXXXXXXXXX #########

     

    Where the X and # characters will be a unique validation string.

     

    Admittedly, the instructions absolutely SUCKED, but that's what we get for using mongrel Ubuntu  🙂

    JB

    Newcomer
    October 13, 2022

    Thank you! So this is just a verification step. And it works.

    -

    Newcomer
    October 12, 2022

    Same here... Any confirmation from Zoom yet?

    Newcomer
    October 12, 2022

    The email apparently passes SPF,DKIM,DMARC tests so seems to be legitimate. But the instruction are so suspicious and there is nothing on their website to back it up. I've opened a support ticket about it. If I get an answer I'll post it here.

     

    Would simply reinstalling the client fix the problem does anyone know? It feels like that would be the safest course of action if there is some uncertainty. You would imagine a fresh install wouldn't suffer from the same problem.

    Newcomer
    October 12, 2022

    Just had a holding response from their tech support. "This issue is already being investigated by our Engineering team. Please don't uninstall the zoom client yet.". 

    Newcomer
    October 12, 2022

    Zoom published a support article. It sounds like more details will be coming soon.

    Newcomer
    October 13, 2022

    I seem to have managed this successfully, but agree that instructions terrible.  I'm running Debian, which I believe is pretty close to Ubuntu.

     

     

    FIRST PART OF INSTRUCTIONS:
    root@newdelldebian:/home/martin# gpg --import /home/martin/Downloads/package-signing-key.pub
    gpg: /root/.gnupg/trustdb.gpg: trustdb created
    gpg: key B903BF1861A7C71D: public key "Zoom Video Communcations, Inc. Linux Package Signing Key <***********>" imported
    gpg: Total number processed: 1
    gpg: imported: 1


    INSTALLING dpkg-sig:
    root@newdelldebian:/home/martin# apt-get install dpkg-sig
    Reading package lists... Done
    Building dependency tree
    Reading state information... Done
    The following additional packages will be installed:
    libconfig-file-perl
    Suggested packages:
    ssh libterm-readkey-perl
    The following NEW packages will be installed:
    dpkg-sig libconfig-file-perl
    0 upgraded, 2 newly installed, 0 to remove and 13 not upgraded.
    Need to get 46.3 kB of archives.
    After this operation, 142 kB of additional disk space will be used.
    Do you want to continue? [Y/n] y
    Get:1 http://deb.debian.org/debian buster/main amd64 libconfig-file-perl all 1.51-1 [11.0 kB]
    Get:2 http://deb.debian.org/debian buster/main amd64 dpkg-sig all 0.13.1+nmu4 [35.2 kB]
    Fetched 46.3 kB in 1s (52.8 kB/s)
    Selecting previously unselected package libconfig-file-perl.
    (Reading database ... 299899 files and directories currently installed.)
    Preparing to unpack .../libconfig-file-perl_1.51-1_all.deb ...
    Unpacking libconfig-file-perl (1.51-1) ...
    Selecting previously unselected package dpkg-sig.
    Preparing to unpack .../dpkg-sig_0.13.1+nmu4_all.deb ...
    Unpacking dpkg-sig (0.13.1+nmu4) ...
    Setting up libconfig-file-perl (1.51-1) ...
    Setting up dpkg-sig (0.13.1+nmu4) ...
    Processing triggers for man-db (2.8.5-2) ...

     

    SECOND PART OF INSTRUCTIONS, ADAPTED FOR WHERE ZOOM LOCATED ON MY MACHINE:
    root@newdelldebian:/home/martin# dpkg-sig --verify /home/martin/Software/zoom_amd64.deb
    Processing /home/martin/Software/zoom_amd64.deb...
    GOODSIG _gpgbuilder [40-CHARACTER CODE SHOWN HERE] 1661751162
    root@newdelldebian:/home/martin#