Every Linux release is signed with a key whose private half never touches this server or any repo. When you verify a download, gpg should report a Good signature and this exact fingerprint. We publish it on both this page and the download page so a single tampered page can't fake it — if they ever disagree, don't run the file.
Signing key fingerprint
7409 3BD6 9827 BE9B 244B 11EE CE86 3718 9592 1ABD
AISMITH PDX LLC Release Signing <sheriff@subnetslinger.com> · Ed25519 · created 2026-10-09
Key rotated 2026-10 as a precaution (the earlier 6285 1F0E… key had been copied to removable media; no compromise is known). All current downloads — Linux and macOS — are signed with the key above; the previous key has been revoked (its revocation certificate is published on the Trust page).