On 10/01/2016 09:07 AM, Arqwer wrote:
Documentation says to check digests after I verified an .iso with gpg. Why? 
Doesn't correct PGP signature mean, that .iso is good and came from Qubes 

Its really an alternative to gpg verification, not an additional step. The doc doesn't mention that.


