Below is the GnuPG public key for the signature on my RPM packages.
cat <<EOF > gnu-pub-key
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1.4.9 (GNU/Linux)
mQGiBEmJWL8RBACbLIHjuWBMNSY/VhfrmAurypzGlVowBrHV0uVXcBqRnxOefdqA
qWEy4u9rZZ2d3uRETUylApgDUIq985epWlky9lGm/j3SGYxJ0BEOq+Ca2RA5Z7TH
BWjT1UGM3vd0ZNTjqeGPCDp/oFio/h6FNQD7FEFSZ/9JjPdQH2uWhlCjcwCggtbp
cdLOpFC3Is+G2fSajxTSaP0D/2nlfWHBaja9qQixH2aEOctaSd3sgHdFY+E2DJ1w
HJ0dp+wZmU2M+MQXJ/I77yu9AKAk5VRYbCpD/JG3DT9Y8VHQxPOemXL+kMNSqa+0
f2uHflbyor83DIkfw1yAcDumEEQQtKQ59/ZgKRQO4s5Ifhtjt8tLE39eHED2dgMG
KLfnA/9rD3F90qd18o02gp3sqpWmqhzkcCob0c6MMGdo/4mqpnEf5oTMf9EcArqQ
ThQWkfoBOgEMyo9abpi5JB/7gRlq0QZ2gbJzFKkh02HHSBoAtpO/SL6ugkbswFfZ
94MnEsxCplK8PgL4dvCejib70CxlpaQvRnolQ2C+qgaAUgwyH7RATWFudmVuZHJh
IEJoYW5ndWkgKGh0dHA6Ly93d3cuaW5kaW1haWwub3JnKSA8bWJoYW5ndWlAZ21h
aWwuY29tPohgBBMRAgAgBQJJiVi/AhsDBgsJCAcDAgQVAggDBBYCAwECHgECF4AA
CgkQx8vHYAFNJQzJ4gCdHf/pUEylrSegX97QF/PGk5AyAS0AnAjUQM9dS2pNpwca
ZAJJWyfaDlnjuQINBEmJWL8QCACeHOo7dOza+jnagWx7B4fKZUMovJ62l8Spvm2q
qs1rJ9uAemPSNtYBfPYpChxxlHA69KUAWhsbJjHWdn7z09TpbiLICV+TjmVcAEvT
EzY9+1bBA4jW3ZrFBMP7fLnZVv7Vv5WHV6YlnA3tGmutuJyJ9G8AOgT8rpPNzI2P
AaFNATuMDQo5ytyMC/p81SOYM338f7wMyxW32xf8X87RxGVuvoiq0jK6OYHyUF+O
v6UApCavxoUU9tTSHG5e5XJyFzdN9oU+MzSZy+dGya5KNscvgDEVS6xcQUBE243d
j+WyQWmcf9VHEw4JammRf6rqOXflfCUh+Te3GiD0JNOgi+b3AAQNB/0S6holUbqi
Vccc2S3fC5KOzHLCVu/1YsLRuKzTZ4l1YRiQ8yvt+LmzTz7jD1tO2G+AP9e1vkPy
c0kaKWvIDEi1CcSy7YoLoRLPdkvIAu/jFZ4LQ4sNAE64S2cVuRjFwvPLxy5bgHor
UmB8FLTiISi0oqtr1hbA/gNlK/XPAIharEdQ2Q27S3ElipqwYy5YcF/tnyQyWsPr
TefRRIPvMsqx2FuvaPpiFqgtcGhda+13Da9VIiSuNF2sOR7ogC9/l/KY/BhT/dGJ
CjpnDmVMvQkSotlXyh9GPuTfhaiY4KhUvcBU8w/VJNiqShLwDazSS/yaBa75WXvb
gV0a/q17ZnbuiEkEGBECAAkFAkmJWL8CGwwACgkQx8vHYAFNJQzSrACfflR0jLJc
ZOuA/UUjHThcxJEwYQ4An0yeKCebvtCjOhZ8adaG0dk1yPyJ
=pFcF
-----END PGP PUBLIC KEY BLOCK-----
EOF
When you would like to check digital signature, you need to import the
public key into the RPM database:
rpm --import gpg-pub-key
You have to the above once. After the digital signature is imported you may any time issue the following
command to verify the package
rpm -K package.rpm