Forefront IT Security Services

Verifying a Forefront document

Every report, proposal and invoice we issue is cryptographically signed. You can confirm a document came from us and that nobody has altered it since.
Signing key fingerprint

A7D5 3B8F 5BA5 7231 B7C7 177A C466 3B25 0044 D5E4

Forefront IT Security Services (Report Signing) <[email protected]>

How to check a document
If you received a .asc file alongside the document

Keep both files in the same folder. Import the public key above, then run:

gpg --import forefront-report-signing.asc
gpg --verify "Your-Report.pdf.asc" "Your-Report.pdf"

Or, with Kleopatra or GPG Suite installed, simply double-click the .asc file.

If you received an encrypted .gpg file

Nothing extra is needed. The signature travels inside the file, so your PGP software names the signer at the moment it decrypts.


Reading the result

gpg: Good signature from "Forefront IT Security Services (Report Signing)"

The document is exactly as we issued it.

gpg: BAD signature from "Forefront IT Security Services (Report Signing)"

The document has been changed since we signed it, even by a single character. Do not rely on it — please contact us.

About the "not certified" warning

You will probably also see WARNING: This key is not certified with a trusted signature. That is not a problem with the document — it appears on a good signature too. It only means you have not personally vouched for our key yet. Check that the fingerprint above matches the one your software reports, and you have confirmed the key is ours.


This key signs documents only — it has no encryption capability, by design. If the fingerprint here ever differs from one you have seen before, or a signature fails, contact us at [email protected] before acting on the document.

Forefront
UK Penetration Testing & Red Team Operations
Loading...