-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-punbb-14.0-jessie-amd64-xen.tar.bz2.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-punbb-14.0-jessie-amd64-xen.tar.bz2 921731b7013dad3b8bcd19264fac67b6 $ sha1sum turnkey-punbb-14.0-jessie-amd64-xen.tar.bz2 b08cf2cbaa1e5636b7f278255898c40d71b9697f -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMdiCAAoJEIXCXpWhbrlN1GIIAKl9+Y6aI06NzqhIXa6lwf7j Y1mJk7AA7p568IP05if9J0v4AI40RZGTEw4piSDJ8+RJ3BBmd3w1DSijLF09RRfY DJbz/TTSlN/nZRLY8lQ4v1dZCbCpTkFeKd8rw2YxXS9kv4fn28DuAr6h+51HLu5o mLDYctgAVZQ2la9+AK+634IqVtQHCJ5FtnKWmhLLOeZc2zVGdHY6s981Zx1vttqw k+Je9V6xhFqYUFTvJDLBXssOBR1pX0cuZtkIQGZScfEbSoj15efnc2RyNCuAx2j0 vAk9cxR2xKNSLtzi+7ZQ8uTmyvRWe9nm2L/E5Z0krfbmfLIl7qbxLP0MQVbdoUw= =ibhx -----END PGP SIGNATURE-----