GPG validation Key installation


I just got notification to install a new GPG validation key. I tried what they suggested (VERY poor commands mixed with comments!!) and got nowhere. I am running ubuntu (latest stable version). Any and all help would be appreciated.



Zoom published a support article. It sounds like more details will be coming soon.

I'm in the same boat too. The email almost looked like a phishing attempt. There is no mention of GPG key rotation on your website.


I received a message from "Zoom Video Communications <***********>" stating that they will be retiring the current key pair used to sign the Linux client on November 2, 2022, and gives the instructions referred to by adit47.


I am somewhat reluctant to follow the instructions, given the many instances of phishing, and would request from this community assurance that this is legit!  I have not gone so far as to test the commands recommended so I cannot comment on their efficacy. 



The command suggested may work in Ubuntu but I am running Manjaro (which is based on Arch), so I have no idea how to proceed.


Any Manjaro or Arch-based knowledgeable people out there who can help?


Same here. The commands are a garbled mess, and neither one works. All I get is error messages when I run them. I am pretty sure that the email comes from, so it's most likely legitimate, but I am at a complete loss as to what to do now.


HEY ZOOM! Does this mean my Linux client will stop working on November 2, 2022? If so, then how in the world do I fix it? Uninstall, then re-install the client after November 2?


I also received the e-mail and wonder if it was a scam too... it is so suspicious that it is not commented on the web...

I would wait until it is announced there...   however it looks like the kind of instructions you would receive to install a new gpg key:

``` gpg --import ~/Downloads/ ```

``` dpkg-sig --verify ./zoom.deb ```


I'm also concerned about the email I received resembling a phishing attempt. I can't find anything on the website referring to this. Please Zoom folks, publish something or give us a link.


I think I can help. This appears legit..

After you run gpg command, download the latest Ubuntu client from the download center:

zoom_amd64.deb                     (or equivalent for your OS)

run dpkg-sig --verify ./zoom_amd64.deb            (you may have to be in the /Downloads directory for this to work).

You'll receive:




Where the X and # characters will be a unique validation string.


Admittedly, the instructions absolutely SUCKED, but that's what we get for using mongrel Ubuntu  🙂


Thank you! So this is just a verification step. And it works.



Same here... Any confirmation from Zoom yet?


The email apparently passes SPF,DKIM,DMARC tests so seems to be legitimate. But the instruction are so suspicious and there is nothing on their website to back it up. I've opened a support ticket about it. If I get an answer I'll post it here.


Would simply reinstalling the client fix the problem does anyone know? It feels like that would be the safest course of action if there is some uncertainty. You would imagine a fresh install wouldn't suffer from the same problem.


Just had a holding response from their tech support. "This issue is already being investigated by our Engineering team. Please don't uninstall the zoom client yet.". 


I seem to have managed this successfully, but agree that instructions terrible.  I'm running Debian, which I believe is pretty close to Ubuntu.



root@newdelldebian:/home/martin# gpg --import /home/martin/Downloads/
gpg: /root/.gnupg/trustdb.gpg: trustdb created
gpg: key B903BF1861A7C71D: public key "Zoom Video Communcations, Inc. Linux Package Signing Key <***********>" imported
gpg: Total number processed: 1
gpg: imported: 1

root@newdelldebian:/home/martin# dpkg-sig --verify /home/martin/Software/zoom_amd64.deb
Processing /home/martin/Software/zoom_amd64.deb...
GOODSIG _gpgbuilder [40-CHARACTER CODE SHOWN HERE] 1661751162



From the support article I checked the fingerprint.

For releases after November 2, 2022, the Linux and Docker GPG signature thumbprint will change from "Key fingerprint: 3960 60CA DD8A 7522 0BFC B369 B903 BF18 61A7 C71D" to "Key fingerprint: 59C8 6188 E22A BB19 BD55 4047 7B04 A1B8 DD79 B481".


However the key that is linked from the email still has the old gpg fingerprint.


Same issue here. After following the instructions from the email, downloading and importing the (allegedly) new gpg key, instead it appears to be the *OLD* key that I downloaded and installed. Zoom Support needs to provide a link to the correct, new key to download.


After importing I ran this command => gpg --fingerprint

... and here is the output:


pub rsa2048 2015-06-07 [SC]
3960 60CA DD8A 7522 0BFC B369 B903 BF18 61A7 C71D
uid [ unknown] Zoom Video Communcations, Inc. Linux Package Signing Key <***********>
sub rsa2048 2015-06-07 [E]


Notice the fingerprint is that of the OLD gpg key.



The official instruction still seem somewhat inaccurate and misleading.


I downloaded and installed the new version of Zoom (5.12).


To check the result of this the command:

apt-cache policy zoom

gave the result:
Version table:
*** 100
100 /var/lib/dpkg/status


Then I followed the instructions to install the new key.


Again, to check the result of this, the command [as root]:

gpg --fingerprint

gave the result:

pub rsa4096 2022-08-18 [SC]
59C8 6188 E22A BB19 BD55 4047 7B04 A1B8 DD79 B481
uid [ unknown] Zoom Video Communications, Inc. <***********>
sub rsa2048 2022-08-18 [A]
sub rsa2048 2022-08-18 [E]


The program opened up OK.


Thank you @ChuckAtTahoe for the command 'gpg --fingerprint'! 

I believe that the new key is to be applied to the version 15.2.6. As far as I know that version is not out yet. So I am a bit confused as to what you did and what the results you posted mean. Can you please clarify: Did you start by downloading the new key or did you just download the latest version of Zoom (15.2.2 I THINK).


Hi adit47


As I understood it, 2 November was the important date, after which I believed my version of Zoom (running on Debian linux) might no longer work, so the steps above were what I did to download and install the latest version (at that time), then the new key, and all has been working fine since.  If I've missed anything, I'll be grateful to know.


I recently had the opportunity to do the same for about 3 computers all running Ubuntu. It seems to work out just fine as described in the support article that I was directed to by Zoom (basically the same as we had all received earlier but a bit clearer). I DID have a whole bunch of stuff go by when I tried to validate that the key had been installed. Apparently there was a whole bunch of stuff that needed "fixing" on my computer that had nothing to do with Zoom. But it doesn't seem to have affected anything else.  Thanks to everyone for your rapid response to my original post and to the Zoom folks for their responsiveness.


I am very interested on this as well. 

