Verifying signatures
You will need gpg
and our release signing key 7A73FE77DE2C4027
. Note that you can get it:
- from our website: https://acinq.co/pgp/drouinf.asc
- from github user @sstone: https://api.github.com/users/sstone/gpg_keys
To import our signing key:
$ gpg --import drouinf.asc
To verify the release file checksums and signatures:
$ gpg -d SHA256SUMS.asc > SHA256SUMS.stripped
$ sha256sum -c SHA256SUMS.stripped