Verifying downloads¶
Each file on the download page is accompanied by an OpenPGP signature (a file with the
same name as the package and the extension “.asc”).
It allows you to verify the file you’ve downloaded is exactly the one we intended you to get.
Info
binjr’s automatic update feature uses the same signatures to verify the integrity of the package it downloads before installing it.
Installing GnuPG¶
First of all you need to have GnuPG installed before you can verify signatures.
Verifying signatures¶
-
Download the binjr developers signing key
-
Import the public key:
-
Verify the signature for the package you would like to authenticate:
Tip
Make sure you have downloaded both the package and its signature (.asc).
If the verification is successful, the program should output something along these lines: