sendmail.org

How to verify the PGP signature of Sendmail

IMPORTANT NOTICE: If you download the sendmail distribution you MUST verify the PGP signature. Do NOT use sendmail without verifying the integrity of the source code. The PGP signature is stored in a file ending with .sig. First you have to get the current PGP signing keys, e.g., from your favorite PGP keyserver or from ftp.sendmail.org or one of its mirrors. Please check the PGP/ GPG documentation about the web of trust. Notes: