-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-owncloud-14.0-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-owncloud-14.0-jessie-amd64.iso a634ac2369d00c194ac46f3597d57b27 $ sha1sum turnkey-owncloud-14.0-jessie-amd64.iso 633ea73023cc901a9e4de9fb7e46b36565d65ea8 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJV7BrpAAoJEIXCXpWhbrlNDlEH/RKlyZb++WfiCMPdg0JdLPnU q9RA6iFNNQiu+U3at0K2arpGVjzNKizVY5Eqbeh2DheJk6irLEe9gLjf1GJaN5rO hXZewozrZ3QxieheSDl3DHzA429O46ToEWjkg3BUt3XELUFvJXWwx/xrr2YEjgdw gqICdfg30J2gAVXuV7G45eG/AfDYpVrGfhjUHpg6oJTpcxzsGRu3hrXPx5jqj5FI va/MAoUeg/YsNRVWA76P8ThtEUwVVonLKfpnxHZH0/i0AYbUNAC8Sw/dNaylB9Ps bXDqwNZ9ikJgUEnVjz3K7M6BM41m4i6qutuBYrwWfL8CA08DXLUmRj1OUv7vU/8= =GVY7 -----END PGP SIGNATURE-----