Verifying Signed Packages

After downloading a package, check that the SHA-256 checksum matches the package's .md5 file. PerCGI packages are signed by Julien Nadeau ( Download our KEYS file along with the package's .asc signature, and verify using gpg:

  $ wget
  $ gpg --import KEYS

  $ wget
  $ gpg --verify percgi-1.0.tar.gz.asc

The fingerprints should match:

8F28 B811 60F8 C10E 53EB  F5F1 3AF1 02AD 3D6A 0EB9
CB94 5774 9A4E 7A9A ECF4  3B20 F5BB 8092 C0BB 1FFA