How do I verify a PGP signature?
What GUI (no command line) software or websites can I use to verify a PGP signature?
If I have a message like this
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Because anyone can claim to be me. There's no validation of the user
name or email address when someone posts a comment. While I do try to
remove imposters, some may slip through. By signing my comments using
this technique, anyone can independently verify that I was the author of
the message by validating the signature.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (MingW32)
iD8DBQFFxqRFCMEe9B/8oqERAqA2AJ91Tx4RziVzY4eR4Ms4MFsKAMqOoQCgg7y6
e5AJIRuLUIUikjNWQIW63QE=
=aAhr
-----END PGP SIGNATURE-----
How can I verify the message against the public key to get the same signature back?
This online encryption/decryption PGP site does not allow me to do that.
Here's a short list GUIs that let you verify PGP clear-signed messages [which I've personally used and can vouch for].
Enigmail add-on for Thunderbird
Pyrite, a standalone GUI for Linux
Nautilus (file manager for Linux), with seahorse plugins
If you use the old version of PGP version 6, not the new version 8, you'll find a GUI interface that lets you store PGP keys and encrypt text, decrypt text and verify signatures with timestamps.
Here's the download link I've uploaded for version 6.