-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-plone-14.0-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-plone-14.0-jessie-amd64.iso e6d4b5266e8951712ec7a6c0bc516137 $ sha1sum turnkey-plone-14.0-jessie-amd64.iso dcac3b5353318050ab5c0226e960e333abf97bb1 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJV7BrqAAoJEIXCXpWhbrlNnvUIANTlOIMywkWlVvGHLyUNo4j5 Ib1v3Bg9gg+5nfU0JfCAMv0Cj8f+Yq41pIAosTyW9OMXaZhYGui8rEpL9ttvOedU 2gBXapRYsUeFx5OpN6Wa4TxorWc7oFaJjY3ffH62vj6i5qlITeKPzTibqsgkhMlp eTqJNupiwNSSpvKe96svAGPWyGQtIoo0C6Gs8pKkVVBdiD3C7XlOSsaDMZp2XaXk RuKWS/2Qs83+cPOyWFusrmiCW7utzp3jmhdNkjuTJ9vLiPIIqmKCcrCyQE1ELRJ8 /oCKnL9BBNLTmiU8GJnPvswIi39CNR6vB2psKWbj14i5/i2jS1ECx4Rt+dZwyDs= =/rcM -----END PGP SIGNATURE-----