-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-punbb-14.1-jessie-i386.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-punbb-14.1-jessie-i386.iso 52dfad6c6d559222fe7fe2136acff538 $ sha1sum turnkey-punbb-14.1-jessie-i386.iso a8f5388d24938f745d80d5f0cdf1cc472b5bea39 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkP0AAoJEIXCXpWhbrlNsxcH/1u9uJhZz9/orx3oUDWYhyrt Q3X6E6OhQoTicugXr0/h8iDWFiLO86mCsNRZ+6yzHAWW1Wo9b/lbqQzYIS4bRAz2 1vBVpJS07c/nlomg9ZvdBV0R2ihn4WA/OnzSjwtSUr3phCUlbcHzRpvfBvRrL52H ygjcPcJh1sQw9BemzHqWO5WO+Pjymic3O7b6x5d01KMiawqQr9bxD4hxc6GzWexw aQPyvnR7PEGIrvUVEgfBsWv84++4W4xo/HF6VEHmPTVjNl3u15u4W+3gWUGZFQD0 rDi2MjzrWaE8EH6ZvafhoF4HMZw+n2GUOPWK9YCmd4zlHgD1o8WFl9NbU+4/DZ4= =eS1v -----END PGP SIGNATURE-----