-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-mahara-14.1-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-mahara-14.1-jessie-amd64.iso 7dfa7f734addc8e70888791ed3f8ad33 $ sha1sum turnkey-mahara-14.1-jessie-amd64.iso 75bc3d61024073c55d97577dad6aa37d9d7e0519 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkPyAAoJEIXCXpWhbrlNQKUIAMUtJDX9F93wlLACcsVYBmc+ gBVFNUDUZ627jATlp1yBYmaJtJJ4x87x5iCPimbrQdye5Xr3IpE9W07RINpWZdPe mc6cXpnqp8n2ii3mk6xS6u8wjwPI32yM9cSPF8a6HLkjGPmwgWHOYPhjBrRzfYxv 4gfEUVUZLJr9308MrYF7tAXxKrD4hD0xB9tbFPLRr4sZQMf0qmRFt66OVKB6UkiR StoU7nlb2fkUO6zRXysOJQV7XIiFKyVUArB8CfY3koAbgZI4y4j9S7F0B8JJOvyc vd+MLN8pGDWR7nRdrkYRa5rgSZPp3jtGIZoa5Gq0vYNc7JRK5ceJuJYykPsgX2M= =6zv4 -----END PGP SIGNATURE-----