Show pageOld revisionsBacklinksBack to top This page is read only. You can view the source, but not change it. Ask your administrator if you think this is wrong. ====== Package signing (GPG) ====== Official Linux packages from astrastudio (Fedora ''.rpm'' and Debian / Raspberry Pi OS ''.deb'') are signed with this OpenPGP key. Use it to check that a file came from us and was not altered. ===== Public key ===== Download: [[https://www.astrastudio.de/GPG-KEY-astrastudio|https://www.astrastudio.de/GPG-KEY-astrastudio]] The file must start with ''-----BEGIN PGP PUBLIC KEY BLOCK-----''. It is a plain key file, not an HTML page, and it does not require a login. ^ ^ Value ^ | UID | ''astrastudio packaging <release@astrastudio.de>'' | | Type | Ed25519, primary Certify, subkey Sign | | Primary fingerprint | ''CC88 632C 5661 DF71 65A8 3BB3 468A 04EF 4DE2 3D60'' | | Primary key ID | ''468A04EF4DE23D60'' | | Signing subkey fingerprint | ''F62A 30B4 4B65 29F5 8733 2E1F D427 6C57 F1A8 7797'' | | Signing subkey ID | ''D4276C57F1A87797'' | | Created | 2026-09-06 | | Primary expires | 2031-09-05 | | Signing subkey expires | 2028-09-05 | Compare the fingerprint on this page with the downloaded file before you import the key. Verify the file: <code bash> curl -fsSL https://www.astrastudio.de/GPG-KEY-astrastudio | gpg --show-keys --with-fingerprint --with-subkey-fingerprint </code> ===== Fedora / RPM ===== Import the key once, then install the shop RPM: <code bash> sudo rpm --import https://www.astrastudio.de/GPG-KEY-astrastudio sudo dnf install ./OnAirScreen_*_Fedora_x64.rpm </code> Check the package after importing the key: <code bash> rpm -K OnAirScreen_*_Fedora_x64.rpm </code> Expected: ''digests signatures OK''. Without the imported key the signature shows as ''NOT OK'' / ''NOKEY'' even if the file is intact. Shop download: [[https://customer.astrastudio.de/|customer.astrastudio.de]] ===== Debian / Raspberry Pi OS ===== The same public key file signs the ''.deb'' packages. ''apt'' does not check the package signature on a local file — verify it with ''debsigs'', import the key, then install as usual: <code bash> sudo apt install debsigs curl -fsSL https://www.astrastudio.de/GPG-KEY-astrastudio | gpg --import debsigs --verify OnAirScreen_*.deb sudo apt install ./OnAirScreen_*.deb </code> Install guide: [[OnAirScreen Linux|Install OnAirScreen from a .deb]]. ===== Notes ===== * The **public** key at the download link above is all you need. Private key files are not required. * When the signing subkey expires, we replace it here and in the key file. The primary fingerprint usually stays the same. * Questions: [[https://www.astrastudio.de/en/contact/|Contact]] gpg-en.txt Last modified: 14.09.2026 16:28by admin