-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-magento-14.1-jessie-i386.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-magento-14.1-jessie-i386.iso 02e192ecca6078ac0fa429628f4cd1cc $ sha1sum turnkey-magento-14.1-jessie-i386.iso cd9433c6a354a421e162fd15a70f5ebc3a3f51a7 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkPyAAoJEIXCXpWhbrlN5toIAIEUrk8Gi5tqQ4dzlkEIlSi5 iZPtKksy4mbxyTaIB7kTy0+s7bg3aOKWSDvwrfTvS99i9ICzsQyqg70gaywIoqpx dUKIf0olmF19D8/9AuQcY9mnTEMbKHt2SQuCtE8ZI2YikRBwM2hV5DAeZ5aw00Aj catP0FhQL0hYY27cKQ0j5XlyNH84QG3nLo1Lq+dQjv3xvEuxcIpKameNpzqPIzQ5 ZwAIS/WRramCwGw3sEipDW66x9xMbHELwI2QrecO9riXTTpnoDzKyPLTRhrdbT9I +5/oVEM6b3KgYLWwOv5IMfFTGaYRvwHil/91s04bcc37sxd79+tyME5If/02Ozc= =QW41 -----END PGP SIGNATURE-----