> The MD5 file is GPG signed. Why not just sign the ISO itself then?
> a GPG key that is publicly accessibleYet the download page didn't provide a link to it until now. Most users probably ignore it.
Also, there should be a verification instruction.
> The MD5 file is GPG signed. Why not just sign the ISO itself then?
> a GPG key that is publicly accessibleYet the download page didn't provide a link to it until now. Most users probably ignore it.
Also, there should be a verification instruction.