-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 To ensure the image has not been corrupted in transmit or tampered with, perform the following two steps to cryptographically verify image integrity: 1. Verify the authenticity of this file by checking that it is signed with our GPG release key: $ curl https://raw.githubusercontent.com/turnkeylinux/common/master/keys/tkl-buster-images.asc | gpg --import $ gpg --list-keys --with-fingerprint release-buster-images@turnkeylinux.org pub rsa4096 2020-02-05 [SC] [expires: 2040-01-31] A8B2 EF42 8781 9B03 D351 6CCA 7623 1C20 425E 9772 uid [ unknown] TurnKey GNU/Linux Buster Images (GPG signing key for TurnKey Linux Buster Images) sub rsa4096 2020-02-05 [S] [expires: 2040-01-31] $ gpg --verify debian-10-turnkey-gitlab_16.1-1_amd64.tar.gz.hash gpg: Signature made using RSA key ID A8B2EF4287819B03D3516CCA76231C20425E9772 gpg: Good signature from "0" 2. Recalculate the image hash and make sure it matches your choice of hash below. $ sha256sum debian-10-turnkey-gitlab_16.1-1_amd64.tar.gz 36e750fc1c61b0960754d45b0762aae617b77f09c621a55ef00f66e4eea1c0f8 debian-10-turnkey-gitlab_16.1-1_amd64.tar.gz $ sha512sum debian-10-turnkey-gitlab_16.1-1_amd64.tar.gz 071cff241f03f23c6a592817554faf717530cf170839ae0322d35e8b1a448fedfbc6a3c99288aa348383f55c3654f9f6a69649b486a36665a95782d63d823e30 debian-10-turnkey-gitlab_16.1-1_amd64.tar.gz Note, you can compare hashes automatically:: $ sha256sum -c debian-10-turnkey-gitlab_16.1-1_amd64.tar.gz.hash debian-10-turnkey-gitlab_16.1-1_amd64.tar.gz: OK $ sha512sum -c debian-10-turnkey-gitlab_16.1-1_amd64.tar.gz.hash debian-10-turnkey-gitlab_16.1-1_amd64.tar.gz: OK Final note, when checking SHAs automatically, please ignore warning noting that some lines are improperly formatted. -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE8ZCki1TcVrLH8k3LrF6wBJPlvBwFAmCzPrYACgkQrF6wBJPl vBwPkA//Sicv8/Ejw8W72imYb8NWirF69esDqulLRBCvU8f6v6xva6JgrTQqEu79 H88H0tMb/t3maq2u8uGkf+fAyZFkOv/KZvi7liRweAqHGrqi4PTEDrfU3MCGNCNZ dyIcPrxIIU7uyx6O34UU6nBu+A/ANvbvd5isK79+tGeTMbGvGK4+np5i/Bc2tbTD jSycULpUGWceZDWdCzwtyn0nc1YjS4ecvJvCNJMH11i2HVxbTVueb9fatDLr9/+y bY133eJN00qpv45608VOefUj9d9+cxf8tMKllN5SBAPcBz4GgTa3i7TD6JnInssr /vFySYCcye5mwFnPsRoSOu68V88XNYnTGMl7JcY/CQhpkXpjHsh7Lc03olnborR1 4lsjQSDqCcpZFTjNfb880E+ROtt+hC3+TNKp+NaHqtRIsIQ0m6iChjAR8Y8C6PUA GNgqISH11XUO1p4Z8gZRPa6g4B1PHFydFCsugma7G+/1Il5SGd3SOWh3RZcfYSNl Vo/PUucVaZxd6kvQuufaYngPfEH7lKoApt6s+zP+27Op+b0/tuLS1DllmtO0MDlR 9NzerbiH+psXnXSWaolkBf0cz8VhrbYlbW4nNLER4AxWfX4clbSrn2jBC9sQRB0T Tas19lUjz+Qe+qJMu8LJ+naJuoKfmU2woVwNzJP7NlF1XSuNt7Y= =bgeL -----END PGP SIGNATURE-----