For an independently authenticated bootstrap, obtain the complete
fingerprint through a channel you already trust. Download the key,
compare all 40 hexadecimal characters, then import it and verify the
release RPM before installation.
D971 CC9D 54F2 1B0C 6BC8 1E34 4479 527D FC68 CF50
curl --fail --location --proto '=https' \
--output RPM-GPG-KEY-BlueSmoke \
https://repo.tsem.nl/keys/RPM-GPG-KEY-BlueSmoke
gpg --batch --show-keys --with-fingerprint \
RPM-GPG-KEY-BlueSmoke
sudo rpmkeys --import RPM-GPG-KEY-BlueSmoke
curl --fail --location --proto '=https' \
--output bluesmoke-release.noarch.rpm \
https://repo.tsem.nl/bluesmoke-release-latest.noarch.rpm
rpmkeys --checksig --verbose bluesmoke-release.noarch.rpm
sudo dnf install ./bluesmoke-release.noarch.rpm
Stop if the fingerprint or RPM signature does not match.