# Unable to verify installer signatures

**URL:** <https://bisq.community/t/unable-to-verify-installer-signatures/6120>\
**Category:** Support\
**Created:** [September 4, 2018, 3:30pm UTC](https://bisq.community/t/unable-to-verify-installer-signatures/6120 "2018-09-04T15:30:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![r6vc8C9r](https://bisq.community/letter_avatar/r6vc8c9r/32/5_5575768a8748004e209b776fc1b2916d.png) [@r6vc8C9r](https://bisq.community/u/r6vc8C9r)\
**Post date:** [September 4, 2018, 3:30pm UTC](https://bisq.community/t/unable-to-verify-installer-signatures/6120/1 "2018-09-04T15:30:47Z")

</div>

I downloaded the latest Windows installer for Bisq, but it failed to validate its signature:

 ![image](https://bisq.community/uploads/default/original/2X/0/0ac6eb8927bfab5d8d92129a3a11246a1ca50ee0.png)

The key fingerprint shown in this dialog didn’t appear to be available on any keyserver, and the signature of the public key provided on the download page doesn’t match this.

Where is the public key for this signature distributed?

---

<div class="post-metadata">

**Author:** ![alexej996](https://bisq.community/user_avatar/bisq.community/alexej996/32/491_2.png) [@alexej996](https://bisq.community/u/alexej996)\
**Post date:** [September 4, 2018, 4:21pm UTC](https://bisq.community/t/unable-to-verify-installer-signatures/6120/2 "2018-09-04T16:21:21Z")

</div>

That is the same key that is provided on the download page.  
You can see that the name of that public key file is the same as last 8 hex-digits of that fingerprint.

---

<div class="post-metadata">

**Author:** ![Homard](https://bisq.community/letter_avatar/homard/32/5_5575768a8748004e209b776fc1b2916d.png) [@Homard](https://bisq.community/u/Homard)\
**Post date:** [September 4, 2018, 4:23pm UTC](https://bisq.community/t/unable-to-verify-installer-signatures/6120/3 "2018-09-04T16:23:42Z")

</div>

Here’s the result in CLI:  
$ gpg --fingerprint 29CDFD3B  
pub rsa4096 2017-07-27 [SC] [expires: 2021-07-27]  
CB36 D7D2 EBB2 E35D 9B75 500B CD5D C1C5 29CD FD3B  
uid [unknown] Christoph Atteneder [christoph.atteneder@gmail.com](mailto:christoph.atteneder@gmail.com)  
sub rsa4096 2017-07-27 [E] [expires: 2021-07-27]

The key fingerprint is the one of Christoph Atteneder, who managed the last release (v0.8.0).

---

<div class="post-metadata">

**Author:** ![r6vc8C9r](https://bisq.community/letter_avatar/r6vc8c9r/32/5_5575768a8748004e209b776fc1b2916d.png) [@r6vc8C9r](https://bisq.community/u/r6vc8C9r)\
**Post date:** [September 4, 2018, 11:05pm UTC](https://bisq.community/t/unable-to-verify-installer-signatures/6120/4 "2018-09-04T23:05:59Z")

</div>

Ok, great. Thanks!
