Since Nitrux 3.2.1, we’ve signed our ISO images with a GPG key to ensure their authenticity. To verify the ISO’s authenticity using GPG, do the following.
- Download the ISO and the signature file.
- Import the latest public key from the changelog for the new release.
We include links to the ISO signature files in the release announcement that we upload to Sourceforge.
Use these files with the recommended programs in this section.
- Verify the signature using the command below.
gpg --verify path_to_sig_file.sig path_to_iso_file.iso
After you verify the ISO’s integrity and authenticity, flash it to a USB.
