-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-lamp-14.1-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-lamp-14.1-jessie-amd64.iso 7fa6773d3f4be09b6d56e9dc729e2775 $ sha1sum turnkey-lamp-14.1-jessie-amd64.iso 3b018e06abe9d1775ea176663695ec62d25a7d48 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkPyAAoJEIXCXpWhbrlNvTEIANkUH6HdU6dOqRM80TmKvNId 8MppFSvzpXgTVMSyS02QWyrYjNcUgN0Gi6zl5WGj6NcowG1KweFiUsLaoNBYrWnH Y8xmraz0n2d+5Xq9Kaqi30OxuiQFoh6NXFXKNsPQb/XOp2c22rfFlx41Br0h36Bi jGym9U4IB6qASfrmWThu5KWl84SjynNKmW2HBLcMPHykKLtChbiNC4yIDEgDZwVH cj/LOdyxHgWoKtJafxRjO6fZz3Ll/5VcIj/tdkfNyXG+BuR37DvkXtKP4XZqK6hk nmkjfy26FPUMa6cTm7yHPGFRpcMnsjSmy+ogdRBXCyHTngHlLtQeTJaxIV7P9YI= =QG4c -----END PGP SIGNATURE-----