-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 To ensure the image has not been corrupted in transmit or tampered with, perform the following two steps to cryptographically verify image integrity: 1. Verify the authenticity of this file by checking that it is signed with our GPG release key: $ curl https://raw.githubusercontent.com/turnkeylinux/common/master/keys/tkl-buster-images.asc | gpg --import $ gpg --list-keys --with-fingerprint release-buster-images@turnkeylinux.org pub rsa4096 2020-02-05 [SC] [expires: 2040-01-31] A8B2 EF42 8781 9B03 D351 6CCA 7623 1C20 425E 9772 uid [ unknown] TurnKey GNU/Linux Buster Images (GPG signing key for TurnKey Linux Buster Images) sub rsa4096 2020-02-05 [S] [expires: 2040-01-31] $ gpg --verify debian-10-turnkey-mibew_16.2-1_amd64.tar.gz.hash gpg: Signature made using RSA key ID A8B2EF4287819B03D3516CCA76231C20425E9772 gpg: Good signature from "0" 2. Recalculate the image hash and make sure it matches your choice of hash below. $ sha256sum debian-10-turnkey-mibew_16.2-1_amd64.tar.gz 04228dddee702b93047362f8b2f98cc51d916f60d5f5c58c96b30ddc1c2b470f debian-10-turnkey-mibew_16.2-1_amd64.tar.gz $ sha512sum debian-10-turnkey-mibew_16.2-1_amd64.tar.gz 8f7423d80b29d989bbafca0a24fb470d6abf282ab2a17b2420bf84e23d276f3a742b22b17582f7825578c8cb1676bfd0f3eafc03691969f26706172f2512def7 debian-10-turnkey-mibew_16.2-1_amd64.tar.gz Note, you can compare hashes automatically:: $ sha256sum -c debian-10-turnkey-mibew_16.2-1_amd64.tar.gz.hash debian-10-turnkey-mibew_16.2-1_amd64.tar.gz: OK $ sha512sum -c debian-10-turnkey-mibew_16.2-1_amd64.tar.gz.hash debian-10-turnkey-mibew_16.2-1_amd64.tar.gz: OK Final note, when checking SHAs automatically, please ignore warning noting that some lines are improperly formatted. -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE8ZCki1TcVrLH8k3LrF6wBJPlvBwFAmBh2NIACgkQrF6wBJPl vBzc7Q/9H4YbyB+4iRki0vEq0mIW8DQDGuvDdajaIDXAQLRqwj4VEK32hUrl9QsC dqM8niAG/xpbPn8rBO40UT+vBD4rqn01R9KDpafWpvn9SpCBSPMkwEGE91GBq0lx r9/p1GZ5vW0pL/ZO9rrtI8HszZR+Uuz5PdhBE/5/Jb5O6gIvg4R71A+YkVeZ11A2 gc7yayqUnuv6xZX3yypJu7vKqZV3EswFgG55H51MHFDb5+fEzLgydhUGSHXVBqG3 cmfscm0hO29+2Uf+S39d8WyojaF8iJEG3ryJs6Jhg++6KSNgkKUHDdZC+owwc8EL x5GNuujQSgRHA5q1EXeQZxjwVdgDGxhHjSnWq9HbBLYrRgDtimRnxr3yFL6duFMx nFRamM6bzF0l07w0mkot6frQ9LvIADnge08NaOocsHCfQZqs/js2tscK0uROcbAK WjxbgQZKA6pLiZQz9JGMmURY/umPDOyIn8Hsb7AvMm09FUga3nxDu5qB0YnLAPGJ sn+ER4gANxwHv9aVXy2fo0Dc5HNWjzMgznUId2Jy00HLYVvI5IrvQp3yxg90FoE1 yNHNA5iTH0xRr5+yN1xIUrAzeioWtw+Hpfww5u6NIeoJOEGDb2IL7sMpZfZ4m5A3 i+KnOjl2WEzWQFfyXFtJ4nR6IVgKS+rM5IhNYG3Xxiff09DFcLk= =tJLc -----END PGP SIGNATURE-----