Submitted by brittney24 on Fri, 06/25/2021 - 19:04
In your instructions on verifying the source file, you mention D/L'g your key & importing into our keyring (in Linux, many use Seahorse).
If I made a mistake here, I apologize.
But when I d/l the latest key on SF & import it, gpg gives msg, "key D6D447B02B4D4C9D: "Andrew Ziem " not changed."
That is true - I had that key & gpg says it is expired (confirmed in my keyring app).
Now, I have a later? key for you that never expires, but gpg is saying the package bleachbit_4.2.0-0_all_ubuntu2004.deb, was SIGNED w/ the key (ID) above (ending in 4c9d).
Ehm...How can I use the asc file for verification???
The usual gpg way (with --verify), returns me the error: "gpg: not a detached signature".
TIA! :-)
G.