Download the release tarball and the separate signature file:
(Note that earlier tarballs were named descriptor-VERSION.tar.gz and could
Attempt to verify the signature on the tarball:
gpg --verify metrics-lib-2.0.0.tar.gz.asc
gpg --verify metrics-lib-<version>.tar.gz.asc
If the signature cannot be verified due to the public key of the signer
servers and retry:
gpg --keyserver --recv-key 0x4EFD4FDC3F46D41E
gpg --verify metrics-lib-2.0.0.tar.gz.asc
gpg --keyserver --recv-key 0x2B4075479596D580
gpg --verify metrics-lib-<version>.tar.gz.asc
Alternatively you can also download the key from Tor Project's DB:
If the signature still cannot be verified, something is wrong!
But note that even if it can be verified, you now only know that the
