-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-drupal8-14.1-jessie-i386.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-drupal8-14.1-jessie-i386.iso fe8c7ffea044f40b6cd82879184290c8 $ sha1sum turnkey-drupal8-14.1-jessie-i386.iso 72d760a47b9298a733953f33b05719ee963ad5c1 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkPxAAoJEIXCXpWhbrlNB74H/1mBjLcBIn3aqtVzFaPTdfm7 Ti0RTm4uinmUp90yro0227K336VDaJwejJMBMAfD+fuK1zscExgsm9F9vpVaavwU qkPN3zMYs2AxpPkmx/ySdJRQcIzw0L7smXRDpek018WAOmcjuap/+rHjKE2aMHaB w/iRYBZjO+5cwvweEgekgHjsO5R7yEl4hI/X3FIxmf6ZsBe2fuU9ynbMDP4mE0S7 d0e5c0OFCvBwvL3BdN5DhhaAi1aE8VFzfeEzK1WQ06hsGh7/sFqyJg31nCZ9GCUp yfJFBVGPgY9pQ1TQOJzURiezSA2HEcE+M6i19MD3yRYc7428MOSXLuzqGX0Iua0= =5ygG -----END PGP SIGNATURE-----