-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 To ensure the image has not been corrupted in transmit or tampered with, perform the following two steps to cryptographically verify image integrity: 1. Verify the authenticity of this file by checking that it is signed with our GPG release key: $ curl https://raw.githubusercontent.com/turnkeylinux/common/master/keys/tkl-buster-images.asc | gpg --import $ gpg --list-keys --with-fingerprint release-buster-images@turnkeylinux.org pub rsa4096 2020-02-05 [SC] [expires: 2040-01-31] A8B2 EF42 8781 9B03 D351 6CCA 7623 1C20 425E 9772 uid [ unknown] TurnKey GNU/Linux Buster Images (GPG signing key for TurnKey Linux Buster Images) sub rsa4096 2020-02-05 [S] [expires: 2040-01-31] $ gpg --verify debian-10-turnkey-mibew_16.0-1_amd64.tar.gz.hash gpg: Signature made using RSA key ID A8B2EF4287819B03D3516CCA76231C20425E9772 gpg: Good signature from "0" 2. Recalculate the image hash and make sure it matches your choice of hash below. $ sha256sum debian-10-turnkey-mibew_16.0-1_amd64.tar.gz 35b349ef1ef4b7e4f62a122a48b12007280ecfcb88a972b45588c1ec10bc204d debian-10-turnkey-mibew_16.0-1_amd64.tar.gz $ sha512sum debian-10-turnkey-mibew_16.0-1_amd64.tar.gz 44308e1a4ec25f376db9541df23ce1f774b92d0daf9ba73c28d353fc598e2ac65fa5090464a88d9971c491b84390d7ff2d1da4ea694252a991c6b284e5a77580 debian-10-turnkey-mibew_16.0-1_amd64.tar.gz Note, you can compare hashes automatically:: $ sha256sum -c debian-10-turnkey-mibew_16.0-1_amd64.tar.gz.hash debian-10-turnkey-mibew_16.0-1_amd64.tar.gz: OK $ sha512sum -c debian-10-turnkey-mibew_16.0-1_amd64.tar.gz.hash debian-10-turnkey-mibew_16.0-1_amd64.tar.gz: OK Final note, when checking SHAs automatically, please ignore warning noting that some lines are improperly formatted. -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE8ZCki1TcVrLH8k3LrF6wBJPlvBwFAl7BD80ACgkQrF6wBJPl vBwziA/9H9NCxwvab8uEewM2vpX7CTxVWuZD4LZsoJlL1Au0cHTsb0FvrQIloVTk W1AyFhcCFQBPCpBgNQvARxJoAw5bYq7/FYG0hRHpg33S5xSMmfs6hnYHqygmwsfg EWxbvJbTkRWMWD6Jlu9oWKZdEhxfTWjOXK9yTRMEPmOtpFi3db65660EupGa8z2I LwEXgfxcsFSjzpns3r8iFs2ZHrqGW6E+QkZit1zO8pGdP7vWR9dfXcClVEp5jndy V42H4rkjaniCoemkFeOXGg8vDPHQISZe3DoDwowJ9bDZdOvTmVPNuixSwl53H8YM jRc9oCt32M7jMPQcK4Q1H2Nte1zMg4uVr/S452ZzCF+GpJvIm7BCW3sxFzkbMplP Z+kNX2WJQLTAmGIJipbGKann2oPxZZVvDYo2aPqZWpgWxdMmcW5Yo5CQpXNM/KfT j6AsQp3VNleQUHwvA7+GqeNnugZ8m5FueumICyzBJTqTV4roycmLqktxfxrgWb31 1wzAJuv5keh6bFBRt8fDG6mynJxqr7qaDwV8apUtUbaTUSelYvYoYtVta+sG/OfN mD/eH14M12EozpYYr43M2Ry88RV9MuiVCt8mVFTlPVIvLJRG3KQzt7Mv3nJC1enm uHuAh/+M92aZ/8vE8XI36+RB6g/qQN8hYSQvGT9XOoq46ceCDk0= =UQPO -----END PGP SIGNATURE-----