BAD signature from "Debian CD signing key <debian-cd@lists.debian.org>"

Viewed 637

debian8 lxde iso file and signature file downloaded.

ls
debian-8.8.0-amd64-lxde-CD-1.iso    SHA1SUMS  SHA1SUMS.sign  

To check it sha1 commands.

sha1sum   debian-8.8.0-amd64-lxde-CD-1.iso
28bc1fefa093de96879be36a14b00c4991ce9cec  debian-8.8.0-amd64-lxde-CD-1.iso
grep  'lxde'  SHA1SUMS
28bc1fefa093de96879be36a14b00c4991ce9cec  debian-8.8.0-amd64-lxde-CD-1.iso

The two sha1sum strings are same.

gpg --keyserver keyring.debian.org --recv 6294BE9B
gpg --verify  SHA1SUMS.sign  debian-8.8.0-amd64-lxde-CD-1.iso

An error occur.

gpg: Signature made Mon 08 May 2017 02:28:21 AM CST using RSA key ID 6294BE9B
gpg: BAD signature from "Debian CD signing key <debian-cd@lists.debian.org>"

1.Why BAD signature from "Debian CD signing key "?
Is something wrong for the debian public key?

2.It is not a smarty way to get sha1sum with sha1sum debian-8.8.0-amd64-lxde-CD-1.iso and grep 'lxde' SHA1SUMS ,then to compare the two output strings by eyes.

1 Answers
Related