-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-fileserver-14.0-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-fileserver-14.0-jessie-amd64.iso 6ca6ea8a83b5b80f656f232e93860004 $ sha1sum turnkey-fileserver-14.0-jessie-amd64.iso bf4095b07fe12597fc53dcb133e3f942a2a7f53c -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJV7BroAAoJEIXCXpWhbrlNe8YH/18MO7gFAoZCWFKdu9AwFC7r vvP+08WJ/nxgK7s7zm1xzIpBvtNkRJLWY5JMCO0saYM6afsgGrez8Nh+V1BZol9L tJAKyyA0OFqVVTvXPaQaG/zNIa3qEyUkyroiTMBkhcnMEz8owRg2pq/5V6q3bQF2 wFQNiq4jThMJMHJKx3VixbWe7wd13/pThewnfI/un3AIgcjbKQlOJPdo2LySSOL6 VDxnp7MsM1onpYWk45JZwoUXZMV0a3RLvsXzFmYM+WIONqHJ7hdzOmjtZwTnl80C KIiaLEC7vTmJYH+NY+GIx0Dp2hiYkQKOD2s5c8jOBCTEnhg3qVkIhuCoL+amllg= =20t+ -----END PGP SIGNATURE-----