Table of Contents

Package signing (GPG)

Official Linux packages from astrastudio (Fedora .rpm and Debian / Raspberry Pi OS .deb) are signed with this OpenPGP key. Use it to check that a file came from us and was not altered.

Public key

Download: https://www.astrastudio.de/GPG-KEY-astrastudio

The file must start with —–BEGIN PGP PUBLIC KEY BLOCK—–. It is a plain key file, not an HTML page, and it does not require a login.

Value
UID astrastudio packaging release@astrastudio.de
Type Ed25519, primary Certify, subkey Sign
Primary fingerprint CC88 632C 5661 DF71 65A8 3BB3 468A 04EF 4DE2 3D60
Primary key ID 468A04EF4DE23D60
Signing subkey fingerprint F62A 30B4 4B65 29F5 8733 2E1F D427 6C57 F1A8 7797
Signing subkey ID D4276C57F1A87797
Created 2026-09-06
Primary expires 2031-09-05
Signing subkey expires 2028-09-05

Compare the fingerprint on this page with the downloaded file before you import the key.

Verify the file:

curl -fsSL https://www.astrastudio.de/GPG-KEY-astrastudio | gpg --show-keys --with-fingerprint --with-subkey-fingerprint

Fedora / RPM

Import the key once, then install the shop RPM:

sudo rpm --import https://www.astrastudio.de/GPG-KEY-astrastudio
sudo dnf install ./OnAirScreen_*_Fedora_x64.rpm

Check the package after importing the key:

rpm -K OnAirScreen_*_Fedora_x64.rpm

Expected: digests signatures OK. Without the imported key the signature shows as NOT OK / NOKEY even if the file is intact.

Shop download: customer.astrastudio.de

Debian / Raspberry Pi OS

The same public key file signs the .deb packages. apt does not check the package signature on a local file — verify it with debsigs, import the key, then install as usual:

sudo apt install debsigs
curl -fsSL https://www.astrastudio.de/GPG-KEY-astrastudio | gpg --import
debsigs --verify OnAirScreen_*.deb
sudo apt install ./OnAirScreen_*.deb

Install guide: Install OnAirScreen from a .deb.

Notes