-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-symfony-14.0-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-symfony-14.0-jessie-amd64.iso ce626b72afa5b3dd19adb3f14abae808 $ sha1sum turnkey-symfony-14.0-jessie-amd64.iso 9b603d4d6d316fb873ccc1b209a411e23a5c7381 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJV7BrqAAoJEIXCXpWhbrlNNloIALT/+AD4LjoMpD6c6v4VVseb 3H7YVeWTI2ouMj8QLAVr7XOHkLDra1rLKFx/wrF+ya4BrgDa8+8EIvoU2a6MOVQs Yk6MT9OR+/qT2Slyquv07/Wg3nrB6kG7A01XZjzJHeT8FiiXNyc4rfkG0iTH950F T9p7FNNLzTqh8G/ufzaYeqI8DTS1KoxDXFgtlRmFY1JwhkzmcryKx0QO7zVaLYnY 6Aw7/RH1mv79FGpJMFshefOOOap0C6BVarq7uf6MSKk+bx0rXdzoBGa3TmhsAB6Z TXhAzc3Cofq3+TkyTh3vhY69AA2K9nvu4b+z8pYnWe/IjHQo8zZcYeH5qwc20GU= =fBaq -----END PGP SIGNATURE-----