I welcome your provision of the signify tool. What I still do not
know is
where on install55.iso I can find the pubkey and the sigfile for
verifying
the iso by itself (test run) as well as further isos (many Linux
distros use
the root directory for these files). You did not 'forget' to ship
these files,
did you? I just please you to put sth. like a README there to make new
or low-brow users know which tool to use i.e. signify and where to find
the pubkey and signing data and the session length. The session length
is the third important parameter to know when verifying already burnt
.isos because they tend to be zero padded at the tail (disregarding this
fact will usually make the verification fail).
What I know up to know is that I can boot into the CD-shell, mount cd0a,
unpack base55.tgz and the *.pub files in ./etc/signify. However then when
it comes to verify cd0a signify does neither accept input from /dev/cd0a
nor from /dev/stdin. Additionally I can still not find the .sig file for
the CD.
To my mind it would also be a nice idea to have the session length i.e.
232294400 for install55.iso of 5.5 somewhere. The rest can be tested by
dd and od to be zeroes.