I've loaded binary guix 0.16 (the latest), its signature, and ran `gpg --verify' on it as explained here [1]. Here is the output I've got:
~ $ gpg --verify guix-binary-0.16.0.i686-linux.tar.xz.sig gpg: assuming signed data in 'guix-binary-0.16.0.i686-linux.tar.xz' gpg: Signature made Thu Dec 6 19:32:22 2018 MSK gpg: using RSA key 3CE464558A84FDC69DB40CFB090B11993D9AEBB5 gpg: Note: signature key 090B11993D9AEBB5 expired Tue Dec 18 11:11:45 2018 MSK gpg: Note: signature key 090B11993D9AEBB5 expired Tue Dec 18 11:11:45 2018 MSK gpg: Note: signature key 090B11993D9AEBB5 expired Tue Dec 18 11:11:45 2018 MSK gpg: using pgp trust model gpg: Good signature from "Ludovic Court�s <l...@gnu.org>" [expired] gpg: aka "Ludovic Court�s <l...@chbouib.org>" [expired] gpg: aka "Ludovic Court�s (Inria) <ludovic.cour...@inria.fr>" [expired] gpg: Note: This key has expired! Primary key fingerprint: 3CE4 6455 8A84 FDC6 9DB4 0CFB 090B 1199 3D9A EBB5 gpg: binary signature, digest algorithm SHA256, key algorithm rsa4096 [1] https://www.gnu.org/software/guix/manual/en/html_node/Binary-Installation.html#Binary-Installation -- Vladimir