-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-revision-control-14.1-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-revision-control-14.1-jessie-amd64.iso f335de45ea4758840496d7d2cf255087 $ sha1sum turnkey-revision-control-14.1-jessie-amd64.iso ad9453e4310e617aa48d8e8b756ff8bb2e120732 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkP0AAoJEIXCXpWhbrlNm8cH/i/RtvSKVRTVgHqD7cxpDYut BrEE6uSBrLzck6aMdWhjK1viugXcC1T7CFbCU200vW3B0RjtGrPzStz6D9FsGFXq 7LyRLIVIiq18kugp+7oJwPIk/wGj6jdvSNzsl/8S1X+3unw9AqXLc8ivU6u+Wt82 6P0CvroWtAD6dJN+bNZPxtOOsOZPAQA4Cut/dWbwz+RAgWVEYrwKBWzXssNyIRUU Q62OaXZw0nhJ8SB/MVIb0Aa4UqXXIMfdyYuQR6y845AQYJEQxnbK9xZFAXf7UPD5 /k36jKAndMmQ+x0Mdy4wUBKnsXcw4EgIl3qzVRhynxmZrLFVnTCzuh0gEc4pGs8= =wpgJ -----END PGP SIGNATURE-----