How to Verify a Download in Ubuntu with SHA256 Hash or GPG Key

$ sh checksig gpg: Signature made Mon 24 Jun 2013 11:42:58 AM EDT using RSA key ID DCD5C569 gpg: Good signature from "Test User " gpg: WARNING: This key is not certified with a trusted signature! gpg: There is no indication that the signature belongs to the owner. Oddly, to check the signature, with the --verify command, gives : >gpg --verify sol.exe.sig sol.exe gpg: la signature n'est pas détachée i.e. In English, the message gpg: the signature is not detached. But to check and extract the original document, from sol.exe.sig, use the -d command and the -o option :

makepkg (un)helpfully uses "gpg" instead of "pacman-key" to check source files, so there's a mix-up somewhere with gpg home dirs and sudo. perhaps that's intentional

