-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 To ensure the image has not been corrupted in transmit or tampered with, perform the following two steps to cryptographically verify image integrity: 1. Verify the authenticity of this file by checking that it is signed with our GPG release key: $ curl https://raw.githubusercontent.com/turnkeylinux/common/master/keys/tkl-buster-images.asc | gpg --import $ gpg --list-keys --with-fingerprint release-buster-images@turnkeylinux.org pub rsa4096 2020-02-05 [SC] [expires: 2040-01-31] A8B2 EF42 8781 9B03 D351 6CCA 7623 1C20 425E 9772 uid [ unknown] TurnKey GNU/Linux Buster Images (GPG signing key for TurnKey Linux Buster Images) sub rsa4096 2020-02-05 [S] [expires: 2040-01-31] $ gpg --verify debian-10-turnkey-gitea_16.1-1_amd64.tar.gz.hash gpg: Signature made using RSA key ID A8B2EF4287819B03D3516CCA76231C20425E9772 gpg: Good signature from "0" 2. Recalculate the image hash and make sure it matches your choice of hash below. $ sha256sum debian-10-turnkey-gitea_16.1-1_amd64.tar.gz ecb46476051daf58817d8826522666bf7e77d50ae6c2fdcfc05a947c0eb84085 debian-10-turnkey-gitea_16.1-1_amd64.tar.gz $ sha512sum debian-10-turnkey-gitea_16.1-1_amd64.tar.gz 9e25d63d0101343bb2d21885873b25092ccd0dbd0cb30d0dc8007ec2b91404a666b7fafa5864c3a50b3b85616aa7ba8dc90105d829e93b705a2642f834ad1a09 debian-10-turnkey-gitea_16.1-1_amd64.tar.gz Note, you can compare hashes automatically:: $ sha256sum -c debian-10-turnkey-gitea_16.1-1_amd64.tar.gz.hash debian-10-turnkey-gitea_16.1-1_amd64.tar.gz: OK $ sha512sum -c debian-10-turnkey-gitea_16.1-1_amd64.tar.gz.hash debian-10-turnkey-gitea_16.1-1_amd64.tar.gz: OK Final note, when checking SHAs automatically, please ignore warning noting that some lines are improperly formatted. -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE8ZCki1TcVrLH8k3LrF6wBJPlvBwFAmA7b5AACgkQrF6wBJPl vBx+Sg//QtAmNSiniw3Iz33zxW4yFdWvxlPchIltKBb0ze5S7r8AIDt+n/kzcN9x KVnctDg7cgwIObcvr7gNPHQhErjilBXBlTSqnKsG7vifo2uPkPFXyAx8BthjsQzo GUBIrZMn3nvrWLxqiwZtL1OHKn/1lpRjfvL9NBLUxXdAgO+J7XxfAhbxUrLYYNIK qMmpCHeQpyxB3kDKfL5XaQsG2G0IG2Ub3SYT+Scn+FCNDhUl0RXSIkN1ZxsWEtH3 IzfHd7fVx2HxKn8ZBCFMSbwv5sDfFhMiOqsCnjPC+3VvnxZOnLAeJtxAXHapiDOR /zZW4d4XI0cX6U6jPt1uBkuQtYzSLEjWvyWwnejRZXajYPCYvy5/W50NBlm2aIxD f6GPv33hednpUz6TD5Wr0qcguspfmrRuIfM8TtVBW7bPFA9IJCJTyQiYR1AD+iVu X7YHo6bZbF3RrB3uVmKaxjFWUuT35wBmc2jd37zQ7YudgHpZH+9c08b2AMCmGJq+ jqTfkipjqMil0ZQEiapRu5OPfk7culTRqBmiagBQCwhxv+onUnZSB+rQ9Bt0Ctfz 1/n6EVfVUMmd1oPNBEd5R5iAfyTfrHE4tbfh4Jlpvcd/P/PtjKCCtYesDnsQOow8 aOg4BrCudW/57VDWrYa9dMGjnE1gtst4biutC2YeAnhLnXviUAA= =8WNG -----END PGP SIGNATURE-----