This is the signature for the GnuPG 1.0.7 tarball gnupg-1.0.7.tar.gz . Please note, that you should not use a just build version of 1.0.7 to verify this signature but an older version of GnuPG or any other OpenPGP implementation. If this is not possible, please verify the MD5 checksums which are given in the announcement mail and on the webpage http://www.gnupg.org/download.html . The key used to create this signature is certified with the the key 5B0358A2 which in turn has been certified by a lot of well known folks. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) iD8DBQA8zXl9aLeriVdUjc0RAgAXAJ9lDTzu1K95AtumGSB/83YHtEnL0QCfTo8m 1JEOLsT+Rh23h9jKvhYZN08= =VJy1 -----END PGP SIGNATURE-----