-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 To ensure the image has not been corrupted in transmit or tampered with, perform the following two steps to cryptographically verify image integrity: 1. Verify the authenticity of this file by checking that it is signed with our GPG release key: $ curl https://raw.githubusercontent.com/turnkeylinux/common/18.x/keys/tkl-bookworm-images.asc | gpg --import $ gpg --list-keys --with-fingerprint release-bookworm-images@turnkeylinux.org pub rsa4096 2023-05-22 [SC] [expires: 2043-05-17] 2614 7592 087C 0EDE 4214 3B63 7761 DEBA BBCF BA7C uid [ unknown] TurnKey GNU/Linux Bookworm Images (GPG signing key for TurnKey Linux Bookworm Images) sub rsa4096 2023-05-22 [S] [expires: 2043-05-17] $ gpg --verify debian-12-turnkey-wireguard_18.1-1_amd64.tar.gz.hash gpg: Signature made using RSA key ID 26147592087C0EDE42143B637761DEBABBCFBA7C gpg: Good signature from "0" 2. Recalculate the image hash and make sure it matches your choice of hash below. $ sha256sum debian-12-turnkey-wireguard_18.1-1_amd64.tar.gz 678a67743ee14ad882ea8b66d5d97d308dc4dfbea1c8d06ed5d673ea064f741b debian-12-turnkey-wireguard_18.1-1_amd64.tar.gz $ sha512sum debian-12-turnkey-wireguard_18.1-1_amd64.tar.gz ae77221b512f2f049c9c20c68e4551365c6c56b5bed754f6268af232afb111e3bea4ff280433b50e578921ce5eb8a3284639a7e926a013b12b549c0c5fa9fbbc debian-12-turnkey-wireguard_18.1-1_amd64.tar.gz Note, you can compare hashes automatically:: $ sha256sum -c debian-12-turnkey-wireguard_18.1-1_amd64.tar.gz.hash debian-12-turnkey-wireguard_18.1-1_amd64.tar.gz: OK $ sha512sum -c debian-12-turnkey-wireguard_18.1-1_amd64.tar.gz.hash debian-12-turnkey-wireguard_18.1-1_amd64.tar.gz: OK Final note, when checking SHAs automatically, please ignore warning noting that some lines are improperly formatted. -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE0achB3UVKiMsY4ckkPLGHN5q3jcFAmcCZYcACgkQkPLGHN5q 3jeRlg//UWsoo9hjbCAldvjr4EyLfMqoh7ZOg+3qBLQHaDxkUjpbwcS/xc9CUZjF lN1kDdye446ZWfSUREeEcTfxLWjbJuJJxgBmMYzB9XNgKUzai8oA2PxaTZ4luole 1vr5nI3TfeRmMEdpQHz48eR6EsG9IrRKDjJLRpWji2pEehSRjxOlIczLGC8XMXBW M4FlJk24V6MVN3U3NfCvAn4eNFAYbiY/8uHurotJmwIMH/0xVxXjN/BgvZnkijAM NkTNYCVDS8w6PeA6uKbqjYYuM4Ytrnrfc7Yox83nYfc+sxP03rPZQy7HVUeDiV2C kj2hznW+VzqWZMwiWWBau/KcJFVCoCfTx+/zGNSiBuPYs87BTpTRjZEyJHTmsMX5 Y6UPda6bxeqafkPW66nDWig95h4HSqo03DqVG82tKe2LHJX3qi+PWSwbR9xFLfQj qlZm/ZUyS2O64FPLhuIp3ZRoh1P3pkXwPIGcBvl0e265pKqbtSxFGDOMNbAsQ1HL p9XT5DxVGNXrwyI2J17yQimZ3S1lLKxadyHyYpq82zEWbxmve9ZEDXbaExdHRQct /gHZ3m6nLHXwTb+EVms27bbBXtjzj0Hhnb8kMPj7thGY4IY121MP8tzdPqnt7NH2 /IJRdozxHy4mQLs+Ehi+vWhzkv46ToYQkM3TgbJE3YtTy9NiJak= =JNFI -----END PGP SIGNATURE-----