-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 To ensure the image has not been corrupted in transmit or tampered with, perform the following two steps to cryptographically verify image integrity: 1. Verify the authenticity of this file by checking that it is signed with our GPG release key: $ curl https://raw.githubusercontent.com/turnkeylinux/common/18.x/keys/tkl-bookworm-images.asc | gpg --import $ gpg --list-keys --with-fingerprint release-bookworm-images@turnkeylinux.org pub rsa4096 2023-05-22 [SC] [expires: 2043-05-17] 2614 7592 087C 0EDE 4214 3B63 7761 DEBA BBCF BA7C uid [ unknown] TurnKey GNU/Linux Bookworm Images (GPG signing key for TurnKey Linux Bookworm Images) sub rsa4096 2023-05-22 [S] [expires: 2043-05-17] $ gpg --verify debian-12-turnkey-snipe-it_18.0-1_amd64.tar.gz.hash gpg: Signature made using RSA key ID 26147592087C0EDE42143B637761DEBABBCFBA7C gpg: Good signature from "0" 2. Recalculate the image hash and make sure it matches your choice of hash below. $ sha256sum debian-12-turnkey-snipe-it_18.0-1_amd64.tar.gz c3da5fbc961b66c70b8879244e1a0f6844e7b2f891dd5be48e88ee4fde0620fe debian-12-turnkey-snipe-it_18.0-1_amd64.tar.gz $ sha512sum debian-12-turnkey-snipe-it_18.0-1_amd64.tar.gz 91281a05f1154153647ab46be56c1d05058237f135c1bfab359e78d9b2a6d5f2d66e248aec5bf7aea5bd4a6b1984f96745959f5344cb914b874bae5ca33d125c debian-12-turnkey-snipe-it_18.0-1_amd64.tar.gz Note, you can compare hashes automatically:: $ sha256sum -c debian-12-turnkey-snipe-it_18.0-1_amd64.tar.gz.hash debian-12-turnkey-snipe-it_18.0-1_amd64.tar.gz: OK $ sha512sum -c debian-12-turnkey-snipe-it_18.0-1_amd64.tar.gz.hash debian-12-turnkey-snipe-it_18.0-1_amd64.tar.gz: OK Final note, when checking SHAs automatically, please ignore warning noting that some lines are improperly formatted. -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE0achB3UVKiMsY4ckkPLGHN5q3jcFAmZO8VEACgkQkPLGHN5q 3jcPXg//cUFrysAgiEmg9c/xXqrMJIgvkJ5lNjfuDAsXniVOjSqVltO9cy+GJtKQ fl3z0M9UEgdwDGo/y2RtNei5T/xbP0Zpt3kkhtWYHz5SN3g1T23TWBbA0ZvCca4N 1d092uam1P8bGgc+T+HE2ou5j4FI+KF5MIv6pZctvCAQcSPEuyAtQ9hUwc9MM4Ro ZLCI0/TZYX6zIlbZdQ0fvAvk/YH7rb/wwiRo8R79fEYvvzwY2+Z0IC58NQo2tVuW wyFKhkpJKIFS3DgWMJGN4lJwJ+aa1pZZGC0zajWT/5K+uNqJKjTmBkOjlKE3oAFM 5hToDakH+ymQGhJfEav7ujlYW4aGu5kDP5ozben0bDYjqpzGQlhXh7GIw2H+9aNh Ayh8BZ7Q0buGgCiG9tWEhWTc0V8kFGeV/qSngdhBPFkQkXoEqkoQfknF1U7DmvA5 xjwSHGchWA5p20MgMwB0OIjTfE0Ks2IvxEPoIa93I0bdWq58PE6KMFm9gLFZNnvj aegabnFaELHHe6ttYZPRVNaN2NzPRo7Oz1lxY+lSlxNi3KqCHoThBsW3ZpAKeyAq WoAJQvUJMTACPvkKQCZ2U9NUXt2ItVWXQIm54dSC67Ik7Lfcz0gpWNCpC4/rKWrx ye72bdNCS3+bx4q0YnR0Uwrhd5285c44iLAR2o837VEqmE+7Eds= =Phdb -----END PGP SIGNATURE-----