AlmaLinux OS Foundation signs all of its software packages using a GPG signature key, which is verified by default when installing packages via dnf or graphical update tools. If a package is not signed or has an invalid signature, dnf or graphical update tools will warn the user and will refuse to install it.
It’s recommended to verify the signature of a package before you install it.
AlmaLinux OS 9
rsa4096/D36CB86CB86B3716 (2022-01-18):
AlmaLinux OS 9 <packager@almalinux.org>
Location: /etc/pki/rpm-gpg/RPM-GPG-KEY-AlmaLinux-9
Download: AlmaLinux
Download: pgp.mit.edu
BF18 AC28 7617 8908 D6E7 1267 D36C B86C B86B 3716
AlmaLinux OS 8 #2
rsa4096/2AE81E8ACED7258B (2023-10-10):
AlmaLinux OS 8 <packager@almalinux.org>
Location: /etc/pki/rpm-gpg/RPM-GPG-KEY-AlmaLinux
Download: AlmaLinux
Download: pgp.mit.edu
BC5E DDCA DF50 2C07 7F15 8288 2AE8 1E8A CED7 258B
ELevate
rsa4096/429785E181B961A5 (2021-08-20):
ELevate <packager@almalinux.org>
Location: /etc/pki/rpm-gpg/RPM-GPG-KEY-ELevate
Download: AlmaLinux
Download: pgp.mit.edu
74E7 F249 EE69 8A4D ACFB 48C8 4297 85E1 81B9 61A5
AlmaLinux OS 8 #1
* Expired but remains a trusted key.
rsa4096/488FCF7C3ABB34F8 (2021-01-12):
AlmaLinux <packager@almalinux.org>
Location: /etc/pki/rpm-gpg/RPM-GPG-KEY-AlmaLinux
Download: AlmaLinux
Download: pgp.mit.edu
5E9B 8F56 17B5 066C E920 57C3 488F CF7C 3ABB 34F8