% GPG et vérification des clés
sudo apt install gpg dirmngr gpg-agent
gpg --keyserver keyring.debian.org --recv-keys 64E6EA7D 6294BE9B 09EA8AC3
Ce qui donne:
gpg: key 42468F4009EA8AC3: "Debian Testing CDs Automatic Signing Key <debian-cd@lists.debian.org>" not changed
gpg: key DA87E80D6294BE9B: "Debian CD signing key <debian-cd@lists.debian.org>" not changed
gpg: key 988021A964E6EA7D: "Debian CD signing key <debian-cd@lists.debian.org>" not changed
gpg: Total number processed: 3
gpg: unchanged: 3
wget https://cdimage.debian.org/debian-cd/current/amd64/iso-cd/SHA256SUMS
wget https://cdimage.debian.org/debian-cd/current/amd64/iso-cd/SHA256SUMS.sign
Puis :
gpg --with-fingerprint --verify SHA256SUMS.sign SHA256SUMS
Ce qui doit donner:
gpg: Signature made Sat 11 Jan 2025 07:08:10 PM CET
gpg: using RSA key DF9B9C49EAA9298432589D76DA87E80D6294BE9B
gpg: Good signature from "Debian CD signing key <debian-cd@lists.debian.org>" [unknown]
gpg: WARNING: This key is not certified with a trusted signature!
gpg: There is no indication that the signature belongs to the owner.
Primary key fingerprint: DF9B 9C49 EAA9 2984 3258 9D76 DA87 E80D 6294 BE9B