diff --git a/static/install.html b/static/install.html index 16cf3638..a6cd1f5b 100644 --- a/static/install.html +++ b/static/install.html @@ -47,6 +47,12 @@
You should have at least 2GB of free memory available.
You need the unlocked variant of one of the supported devices, not a locked carrier specific variant.
+To verify the download of the OS beyond the security offered by HTTPS, you need the
+ signify tool. Some package repositories refer to it as signify
while
+ others refer to it as signify-openbsd
due to a legacy mail-related tool
+ with the same name. If you don't have a way to obtain signify from a trusted package
+ repository, such as on Windows, skip the additional verification. This is an important
+ step, but it only makes sense if you can chain trust from your existing OS install.
It's best practice to update the stock OS on the device to make sure it's running the latest firmware before proceeding with these instructions. This avoids running into bugs in older firmware versions. It's known that the early Pixel 2 and Pixel 2 XL @@ -88,10 +94,15 @@
The initial install will be performed by flashing the factory images. This will replace the existing OS installation and wipe all the existing data.
-You can download the factory images from the releases page.
-Verify the official factory images using the GPG signature:
-gpg --recv-keys 65EEFE022108E2B708CBFCF7F9E712E59AF5F22A -gpg --verify blueline-factory-2019.04.01.19.zip.sig blueline-factory-2019.04.01.19.zip+
Download the factory images + public key (factory.pub) in order to verify the factory images.
+This is the content of factory.pub
:
untrusted comment: GrapheneOS factory images public key +RWQZW9NItOuQYJ86EooQBxScfclrWiieJtAO9GpnfEjKbCO/3FriLGX3+
Download the factory images for the device from the releases + page.
+Verify the factory images using the signature:
+signify -V -p factory.pub crosshatch-factory-2019.06.23.05.zip
When this signing key is replaced, the new key will be signed with it.
These releases are available as both tags in the source code repositories and official builds.
The factory images are used for the initial installation and can be verified with - GPG. See the installation guide for details.
+ signify. See the installation guide for details.GrapheneOS uses automatic over-the-air updates, but full update packages are listed below for uncommon use cases like never connecting the device to the internet. A full update package can upgrade from any past version to the new version. The over-the-air