// /etc/aether/keys

Security & Signing

Every AetherXOS release artifact is published with a detached GPG signature. Verify before you boot.

Verification

Import the AetherXOS signing key, then verify the ISO with its detached .asc signature:

# 1. Import the signing key
curl -sSL https://aetherxos.dev/api/security/key | jq -r .public_key | gpg --import

# 2. Verify the ISO
gpg --verify aetherxos-1.0.0-x86_64.iso.asc aetherxos-1.0.0-x86_64.iso

# 3. Verify SHA256 (also shown on each Download Center card)
sha256sum -c aetherxos-1.0.0-x86_64.iso.sha256
Signing Key

No signing key registered yet. Admins can publish one from the admin panel.

Security Advisories (CVEs)

No security vulnerabilities or advisories registered. System status: NOMINAL.