$ gpg --verify glibc-2.13.tar.gz.sig glibc-2.13.tar.gz
gpg: Signature made Tue 01 Feb 2011 17:00:21 CST using DSA key ID 6F00984E
gpg: BAD signature from "Andreas Schwab <schwab@redhat.com>"
Use a .sig file to verify that the corresponding file (without the
.sig suffix) is intact. First, be sure to download both the .sig file
and the corresponding tarball. Then, run a command like this:
gpg --verify grep-2.11.tar.xz.sig
If that command fails because you don't have the required public key,
then run this command to import it: