-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-e107-14.1-jessie-amd64-xen.tar.bz2.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-e107-14.1-jessie-amd64-xen.tar.bz2 69ccc963e8cc01b861afc6c466ca6086 $ sha1sum turnkey-e107-14.1-jessie-amd64-xen.tar.bz2 9a91f96cf826f0d3cb789868bc7c863711d54d87 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXDJnyAAoJEIXCXpWhbrlNTWQIAMMS3pR2LC13Vow5n9uCMzou 5xvIZcngOtO6kyxvqVkNOK812eeJdtYnY1NZhQQWGDxy+YVQEO+hSBUXJTkTuM4H YSZZV+IrFp9778g869DVzhBiA/sePZ90kgFaFtDooZKjiX4OyWWkvyAvFjlre8jZ sPOCoaMI85KsF6FCQbKU2bYzp/euiTUg3XwvrAYL35EykVqk8KJvo696e2JpiSMV 5rpOKL0kiHTAqPInQqUcvPMpPzUbhTYZlCzsAUeaGT/oOsub3mUQexmvDBW4eE7R F5EwSl4F6mkwzBVn0C0BDcBtk7ETPze6JUKPho6smUz8Jad2IJlo0TApAMqwRaA= =nZqt -----END PGP SIGNATURE-----