Download the Kicksecure Signing Key

From Kicksecure
(Redirected from KVM/Project Signing Key)
Jump to navigation Jump to search

Get Kicksecure OpenPGP signing key. Verify Kicksecure Downloads, APT Repository and/or Source Code.


Since all Kicksecure releases are signed with the same key, it is unnecessary to verify the key every time a new release is announced. Trust in the key might gradually increase over time, but cryptographic signatures must still be verified every time a new release is downloaded.

This page is strongly related to the Placing Trust in Kicksecure page.

  • Digital signatures: A tool enhancing download security. Commonly used across the internet.
  • Learn more: Curious? Learn more about digital software signatures.
  • Optional: Digital signatures are optional. If you've never used them before, there might be no need to start now.
  • No worries: New to digital software signatures? It's okay, no need to worry.
  • Not a requirement: Not mandatory for using Kicksecure, but an extra security measure for advanced users.

Download the OpenPGP Key[edit]

GnuPG logo

Optional: Complete the steps below if unfamiliar with GnuPG or if they haven't already been performed. This will fix eventual gpg: WARNING: unsafe ownership warnings.

Have GnuPG initialize your user data folder.

gpg --fingerprint

Set warning free permissions.

chmod --recursive og-rwx ~/.gnupg

Select your operating system.

Windows, macOS, Linux

1. Securely download Patrick Schleizer's (adrelanos') OpenPGP key. [1] [2]

Download Kicksecure Developer OpenPGP Key

2. Store the key as derivative.asc.

3. Check fingerprints/owners without importing anything.

gpg --keyid-format long --import --import-options show-only --with-fingerprint derivative.asc

4. Verify the output.

The most important check is confirming the key fingerprint exactly matches the output below. [3]

      Key fingerprint = 916B 8D99 C38E AF5E 8ADC  7A2A 8D66 066A 2EEA CCDA

The message gpg: key 8D66066A2EEACCDA: 104 signatures not checked due to missing keys is related to the The OpenPGP Web of Trust. Advanced users can learn more about this below.

warning Warning:

Do not continue if the fingerprint does not match! This risks using infected or erroneous files! The whole point of verification is to confirm file integrity.

5. Configure the trust level for the GPG key.

Optional. [4]

echo "916B8D99C38EAF5E8ADC7A2A8D66066A2EEACCDA:6:" | gpg --import-ownertrust

The output should create trustdb.

gpg: /home/user/.gnupg/trustdb.gpg: trustdb created
gpg: inserting ownertrust of 6

6. Import the key.

gpg --import derivative.asc

The output should include the key was imported.

gpg: key 8D66066A2EEACCDA: public key "Patrick Schleizer <>" imported
gpg: Total number processed: 1
gpg:               imported: 1
gpg: marginals needed: 3  completes needed: 1  trust model: pgp
gpg: depth: 0  valid:   1  signed:   0  trust: 0-, 0q, 0n, 0m, 0f, 1u
gpg: next trustdb check due at 2026-01-23

If the Kicksecure signing key was already imported in the past, the output should include the key is unchanged.

gpg: Total number processed: 1
gpg:              unchanged: 1

7. Web of trust.

Advanced users can check Web of Trust further below for better security.

Kicksecure or Whonix

1. Configure the trust level for the GPG key.

Optional. [4]

echo "916B8D99C38EAF5E8ADC7A2A8D66066A2EEACCDA:6:" | gpg --import-ownertrust

The output should create trustdb.

gpg: /home/user/.gnupg/trustdb.gpg: trustdb created
gpg: inserting ownertrust of 6

2. Import the key.

Since the key is already available in Kicksecure or Whonix, importing the key is simpler than for other operating systems.

gpg --import /usr/share/keyrings/derivative.asc

The message gpg: key 8D66066A2EEACCDA: 104 signatures not checked due to missing keys is related to the The OpenPGP Web of Trust. Advanced users can learn more about this below.

3. Skip a few steps.

Steps 4. to 7. (which would be required for Windows, macOS and other Linux) can be skipped here. Proceed to step 8. below.

Debian and Derivatives

1. Install extrepo-offline-data.

Because it contains the signing key.

Install package(s) extrepo-offline-data. Follow steps A to D.

A. Platform specific notice.

B. Update the package lists and upgrade the system The Web Archive Onion Version .

sudo apt update && sudo apt full-upgrade

C. Install the extrepo-offline-data package(s).

Using apt command line --no-install-recommends The Web Archive Onion Version is in most cases optional.

sudo apt install --no-install-recommends extrepo-offline-data

D. Platform specific notice.

E. Done.

The procedure of installing package(s) extrepo-offline-data is complete.

2. Configure the trust level for the GPG key.

Optional. [4]

echo "916B8D99C38EAF5E8ADC7A2A8D66066A2EEACCDA:6:" | gpg --import-ownertrust

The output should create trustdb.

gpg: /home/user/.gnupg/trustdb.gpg: trustdb created
gpg: inserting ownertrust of 6

3. Import the key.

Thanks to the extrepo-offline-data package, the key is already available on the local file system and can be imported into the user's keyring. [5]

gpg --import /usr/share/extrepo/offline-data/debian/bullseye/whonix.asc

4. Skip a few steps.

Proceed to step 8. below.

8. Complete the Kicksecure verification steps.

If verifying Kicksecure images, navigate to the relevant verification page below to finish the process:

OpenPGP Key Features[edit]

  • sign/verify Kicksecure images: yes
  • sending encrypted e-mails to Kicksecure developer Patrick: yes

Advanced Users[edit]

OpenPGP Web of Trust[edit]

A few people have signed Patrick Schleizer's (adrelanos') OpenPGP key in The OpenPGP Web of Trust.

Jan Dittberner [6] (Debian Developer) [7] signed Patrick's key. So did intrigeri (Tails developer, Debian Developer); Peter Palfrader (Debian Developer); Richard King; and Michael Carbone (

Users relying on Debian or one of the many Debian derivatives (like Ubuntu) already trust apt, the APT repository of the relevant distribution. This means the Debian keyring can be installed as a trusted source for obtaining Jan's, intrigeri's or Peter's key, to check their signature on Patrick's key.

1. Update the package lists.

sudo apt update

2. Install the Debian keyring.

sudo apt install debian-keyring

3. Extract a signer's key from the Debian keyring and import it into your own keyring.

Here is an example using Jan's key.

gpg --no-default-keyring --keyring /usr/share/keyrings/debian-keyring.gpg --armor --export B2FF1D95CE8F7A22DF4CF09BA73E0055558FB8DD | gpg --import

4. Optional: Try to establish a better trust path to the signer by checking signatures on the signer's key.

Check signatures on Patrick's key.

gpg --check-sigs 916B8D99C38EAF5E8ADC7A2A8D66066A2EEACCDA

The output of the above command should show signatures on Patrick's key, which should include the signer's signature.

Download the signify Key[edit]


Info Advanced users only!


Download Kicksecure signify Key

Further Reading[edit]


When a GPG error is encountered, first try a web search for the relevant error. The security stackexchange can also help to resolve GPG problems. Describe the problem thoroughly, but be sure it is GPG-related and not specific to Kicksecure.

More help resources are available on the Support page.

See Also[edit]


Kicksecure Main/Project Signing Key wiki page Copyright (C) Amnesia <amnesia at boum dot org>
Kicksecure Main/Project Signing Key wiki page Copyright (C) 2012 - 2024 ENCRYPTED SUPPORT LP <

This program comes with ABSOLUTELY NO WARRANTY; for details see the wiki source code.
This is free software, and you are welcome to redistribute it under certain conditions; see the wiki source code for details.


  1. curl --tlsv1.3 --proto =https --max-time 180 --output derivative.asc
  2. Minor changes in the output such as new uids (email addresses) or newer expiration dates are inconsequential.
  3. 4.0 4.1 4.2 The trust level will be increased to ultimately. (This is because the command contains trust level ":6:".)
    The purpose of this command is:
    • A) to avoid the following warning when importing the key. And,
    gpg: no ultimately trusted keys found
    • B) to avoid the following warning when verifying a file signed by that key.
    gpg: WARNING: This key is not certified with a trusted signature! 
    gpg: There is no indication that the signature belongs to the owner.

    Advanced users are free to skip this step or use a different GPG trust level.

  4. Note to wiki editors:
    Hash: SHA512
    untrusted comment: Patrick Schleizer signify public key
    -----END PGP SIGNATURE-----

Unfinished: This wiki is a work in progress. Please do not report broken links until this notice is removed, use Search Engines First and contribute improving this wiki.

We believe security software like Kicksecure needs to remain Open Source and independent. Would you help sustain and grow the project? Learn more about our 12 year success story and maybe DONATE!