I used gpg to check the sha1sum against the one provided in the downloads server. Returned `gpg: Signature made Fri 13 Mar 2015 10:41:29 AM EDT using RSA key ID 7D8D0BF6
gpg: BAD signature from "Kali Linux Repository <[email protected]>"` I kinda thought I was just doing it wrong, but now I wonder if I also have a bad copy. How did you do the checksum?