After having downloaded "Magellan binaries for Linux" and "Magellan binaries for Linux Signature File", I noticed that the "signature file" is a plain text file containing the SHA-256 checksum for the file instead of a signature.
(Note: Once could combine both worlds by clear-text-signing the checksum file, but actual checking may be more complex: You'd have to check the signature of the check sum first, then the checksum)
However this is not the topic of this discussion; the real issue is that the checksums do not match:
So what happened to the checksum?