-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-simplemachines-14.1-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-simplemachines-14.1-jessie-amd64.iso e9c00750c3503dedd92c420fe5297b68 $ sha1sum turnkey-simplemachines-14.1-jessie-amd64.iso 51c84ee8095a41134bfc32d117010a5901f51a84 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkP0AAoJEIXCXpWhbrlNOkMH/RRKUcK1HAs1y4SlrEbzEMh6 mR8bFwr5gRbsDy0OFBnwbAFbHFjx7sdazkUQZgrYgvisbv+5S9z0Po0jrD1xAC8M Itu+BbJuYlbPypPIx5SQH8C+r7+g8poFNWl3FPWqU/C8pQ+aBP1YqKYAhmqq0Pcu Cl/TZfXZF5oOzN1VF/fOfO2QUzgH/m2HcpdVGxJK+v5LFecL2MRhrLp2DcSq550z jWeyKe2vMdnKvvqDd/dq5u2qjPi2mliK4OoNKdjw8W8BvF5bZEmKP6KRfFM+S3x2 Of4fl6dGgY2F2daPKH/wwMEvlsu637L3m7bxACX07HjLN0RFOQVw6eEGVX/W1+8= =ek96 -----END PGP SIGNATURE-----