$ gpg --recv-key 0xBE86EBB415104FDF $ gpg --fingerprint 0xBE86EBB415104FDF ...check it matches fingerprint above... $ gpg --verify SIGNATURE-FILE SOURCE-FILE also, more common: verify a signateure: sha256sum -b yourfile.iso --------------- Verify a file signature: gpg --keyserver-options auto-key-retrieve --verify linux-5.12.7.tar.sign Check the signed hash of a file: gpg --verify SHA256SUMS.gpg SHA256SUMS Same: gpg --keyserver pool.sks-keyservers.net --recv-keys 74F12602B6F1C4E913FAA37AD3A89613643B6201 gpg --verify SHASUMS256.txt.asc