After you import both the master and signing keys, you can check them with 'gpg --check-sigs' which should have output like this: pub rsa4096 2017-03-06 [SC] 5817A43B283DE5A9181A522E1848792F9E2795E9 uid [ unknown] Qubes OS Release 4 Signing Key sig!3 1848792F9E2795E9 2017-03-06 Qubes OS Release 4 Signing Key sig! DDFA1A3E36879494 2017-03-08 Qubes Master Signing Key
(I have the Qubes 4 key but its otherwise the same.) This lists the Qubes master key under the uid for the Qubes release key, showing the release key has been signed by the master. The exclamation mark after "sig" means the signature has been verified as good. Dear Chris, Thanks very much for your patient help with this! I was able to verify all keys and signatures and successfully installed Qubes 3.2 over the holidays. Regards, Kyle -- You received this message because you are subscribed to the Google Groups "qubes-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to qubes-users+unsubscr...@googlegroups.com. To post to this group, send email to email@example.com. To view this discussion on the web visit https://groups.google.com/d/msgid/qubes-users/CAOtZr%3DEZk4tXHkDkaLk7gmjkEikx%3DTyP%3DSeSGnp90O4g4Ho%2BVA%40mail.gmail.com. For more options, visit https://groups.google.com/d/optout.