-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 To ensure the image has not been corrupted in transmit or tampered with, perform the following two steps to cryptographically verify image integrity: 1. Verify the authenticity of this file by checking that it is signed with our GPG release key: $ curl | gpg --import $ gpg --list-keys --with-fingerprint release-bullseye-images@turnkeylinux.org pub rsa4096 2021-08-04 [SC] [expires: 2041-07-30] E10F 6567 0C8E BE42 ED0C 3A49 CCA5 1174 468F 9073 uid [ unknown] TurnKey GNU/Linux Bullseye Images (GPG signing key for TurnKey Linux Bullseye Images) sub rsa4096 2021-08-04 [S] [expires: 2041-07-30] $ gpg --verify debian-11-turnkey-gitea_17.1-1_amd64.tar.gz.hash gpg: Signature made using RSA key ID E10F65670C8EBE42ED0C3A49CCA51174468F9073 gpg: Good signature from "0" 2. Recalculate the image hash and make sure it matches your choice of hash below. $ sha256sum debian-11-turnkey-gitea_17.1-1_amd64.tar.gz a1a70324f4637e7a11a8a2a0aeb02b4f8c0a7a47297fe2740fbb8d0d1eac19a7 debian-11-turnkey-gitea_17.1-1_amd64.tar.gz $ sha512sum debian-11-turnkey-gitea_17.1-1_amd64.tar.gz 6cbb0ef6762bfdb5bca26cec1465c3d53d962082006f2af65f4d734c1b49082a294c409383a700e3fdd2b4e9d1a246db590bc9d978f6756c68f4d795fc3ead10 debian-11-turnkey-gitea_17.1-1_amd64.tar.gz Note, you can compare hashes automatically:: $ sha256sum -c debian-11-turnkey-gitea_17.1-1_amd64.tar.gz.hash debian-11-turnkey-gitea_17.1-1_amd64.tar.gz: OK $ sha512sum -c debian-11-turnkey-gitea_17.1-1_amd64.tar.gz.hash debian-11-turnkey-gitea_17.1-1_amd64.tar.gz: OK Final note, when checking SHAs automatically, please ignore warning noting that some lines are improperly formatted. -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE3YP+u+JWuSop/BuCHkh6RjHW/rYFAmM0CTMACgkQHkh6RjHW /rah9RAAriRCMpADOaghnP8VdZDiZi4RE2RlaKERKLmCMQ6/Rs9rFnPI3JP39lvp qzeYn6rQ8loW0Eh2KHg0M1rqkiOj7GOCY/lqffuSZ5KbIDPtlJPplnT6vFP1qXRQ 2ZoE6++VHbQH/8c2n4cUrZ9v4Vy+Cb3gkFgckuy+DU6f4jcVejDGm+sg+gAZW1iu TWpSF+o4vA8By2zDnuyIE32PlioTzx3qwMHbrLVn5cVO46jUlF0uvkuFMa4C9viz LTU6YvjQMD3z89S8N4iI9VD4xv0i3KSeIYd1Ddljd+t4Bi18v1RJPdBXuvMvSxNn O0/C9MmCIVFvuUovVSWSWO1s+aZeIiaQZUWB7DHBGohVOmmzG28PfLPCQ+NvvgTU oQGExaLiLNrzxfD7iJc++L2dg89ba7mZg2NU+VT8QoRnSYTack8mldOcxVCFal1f q8jO6DGpjv0oT3O6Hu6MNpt3ukIKj/quU6FkEfH4zBqPTfonZQzDzpzLpu9+nbME cqFJATEecaeAjiqdq+uCZArPaCdYzafv9UZFnYd8JD5KpNdgOYtFbzhQwBuwu3CV QiahP238Mq1fePGBIv+bIohKqUsEvlMFJp8QRkb6a617DZrAqaOhDBWTEJWzljjl wx3hJUExlSjC7aJfbK/df8I4YkyE4+FDJHsDOWrFNRbgsqBKXZk= =lT3p -----END PGP SIGNATURE-----