http://uhwikizevog5aj4aiepeseafcxqamnzrpdmnnxaj7y2ek3am4vdoilqd.onion/index.php?title=Verifying_PGP_signatures&action=info
There is a keyfile at http://deb.torproject.org/archive-key.asc which is used to verify the checksums of the Debian and Ubuntu GNU/Linux versions of Tor and Vidalia . For other operating systems (such as Windows or Mac OS), the key must be obtained using another method. Once the user has a keyfile, the key may be imported in the following manner: GNU Privacy Assistant: In the Key Manager , click the Import button.