gpg --version gpg (GnuPG) 2.2.27libgcrypt 1.9.4gpg --import ./OPNsense-23.1.pub # Console output:gpg: no valid OpenPGP data found.gpg: Total number processed: 0
openssl base64 -d -in ./OPNsense-23.1-OpenSSL-dvd-amd64.iso.bz2.sig -out ./OPN_image.sigopenssl dgst -sha256 -verify OPNsense-23.1.pub -signature ./OPN_image.sig ./OPNsense-23.1-OpenSSL-dvd-amd64.iso.bz2# Console outputVerified OK
Because a new key is generated for each release for security reasons.
How can generating a new pubkey at each OPNsense release could be considered safer?