-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 To ensure the image has not been corrupted in transmit or tampered with, perform the following two steps to cryptographically verify image integrity: 1. Verify the authenticity of this file by checking that it is signed with our GPG release key: $ curl https://raw.githubusercontent.com/turnkeylinux/common/master/keys/tkl-buster-images.asc | gpg --import $ gpg --list-keys --with-fingerprint release-buster-images@turnkeylinux.org pub rsa4096 2020-02-05 [SC] [expires: 2040-01-31] A8B2 EF42 8781 9B03 D351 6CCA 7623 1C20 425E 9772 uid [ unknown] TurnKey GNU/Linux Buster Images (GPG signing key for TurnKey Linux Buster Images) sub rsa4096 2020-02-05 [S] [expires: 2040-01-31] $ gpg --verify debian-10-turnkey-mibew_16.1-1_amd64.tar.gz.hash gpg: Signature made using RSA key ID A8B2EF4287819B03D3516CCA76231C20425E9772 gpg: Good signature from "0" 2. Recalculate the image hash and make sure it matches your choice of hash below. $ sha256sum debian-10-turnkey-mibew_16.1-1_amd64.tar.gz cf7540cfedc22ea54b75e642a935a4d770a8002e4543e43cb24fa8da0c4cb164 debian-10-turnkey-mibew_16.1-1_amd64.tar.gz $ sha512sum debian-10-turnkey-mibew_16.1-1_amd64.tar.gz 9b98586ed170435fee3728f1ecfbfcf3d60b54c7ce6f9d80e242a9126111f356f1da4b5681923d93a7b66ff6f9392146c895f5015a691e6ce72d46480af1cfa4 debian-10-turnkey-mibew_16.1-1_amd64.tar.gz Note, you can compare hashes automatically:: $ sha256sum -c debian-10-turnkey-mibew_16.1-1_amd64.tar.gz.hash debian-10-turnkey-mibew_16.1-1_amd64.tar.gz: OK $ sha512sum -c debian-10-turnkey-mibew_16.1-1_amd64.tar.gz.hash debian-10-turnkey-mibew_16.1-1_amd64.tar.gz: OK Final note, when checking SHAs automatically, please ignore warning noting that some lines are improperly formatted. -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE8ZCki1TcVrLH8k3LrF6wBJPlvBwFAl8UCf8ACgkQrF6wBJPl vBwdgA/8DpzpMNZ+6gYDsRjkhbvbrwLYvDtKLngBlBe4bEAvYXVuo7phOaEmONN/ Czwu2IlGiL8KNzE1jzJwwdbe7Bzh+LYZ6m7OtM5P5DmoXuCojqkd7zuctvRMyrfo UUYghhGrBhXvB49p5P0gvn/OVzVnpACqhidTN7qBtUJlbkMbCgoVsKDFdVBehZmI pt+CB0Uu8hmHQvZE4MTyEuNYyNEeiWtTFj9rPvvax1s64M8dwuk9exQyq9nv0pYm 8QnBri3gjxLwxdiQQ3ju2TS4nFrwZDY0Xe7jfcQ39YguRqaSuQdcuTCC6unPajGI 4BsR3E9SaKUOhgxnoNzuujR3k7Yu0Iw4GU9XB/Z1079t3a6fjfmJiFn2hJrW0At6 yw6mkC8eeDit3tfKMV1eYCj6HQmcM83N8BdFngJkB8y235GlfhSq2p9jlgJNZX0P 4Zk7EToThCWOgiVkPezFAm9Ti1ekoVFPZDWppfbB4tQWZK3RVwHDn5I+L9jT5mEd vwic2dZQIvka8z//OAhALGjf7RlotBm0Ffr+/KqoWFVV5tWjLw0SHHWKPDxDrWl3 //l1ojeycW4fnkBlfAiTJGWzoIV56K5OHbPEBL9H+U35QO6FsLO39CjanaO6+VRn iLO83NVCuTX13sBMzbVfS6X9ZWRRqOs4+CnoUNJgp3UIr9NZWwg= =9eSL -----END PGP SIGNATURE-----