The signature on 0.5.5c/sha256sum.txt.asc seems to be broken.
Steps to reproduce:
$ wget http://downloads.sourceforge.net/project/retroshare/RetroShare/0.5.5c/sha256_sums.txt.asc $ gpg sha256_sums.txt.asc gpg: Signature made Wed Jan 29 13:41:05 2014 CET using DSA key ID C737CA98 gpg: BAD signature from "Cyril Soler <csoler@sourceforge.net>" [unknown]
Yes, I can confirm. Signature check fails here, too. Nastyness going on?! I just reinstalled my computer and am refraining from reinstalling RetroShare until this is fixed.
Also: would be cool to get some pointers as how to know the used key is indeed a trustworthy one.