-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-concrete5-14.1-jessie-i386.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-concrete5-14.1-jessie-i386.iso 11426c896b8d96316e6bb1c2c6fdc437 $ sha1sum turnkey-concrete5-14.1-jessie-i386.iso eae9ada96262cf73752ba1c4f6efc504e985dfe9 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkPxAAoJEIXCXpWhbrlNr34H/0/9iVIZGlf3uvRVsrhxDEYV XSqo8fP1Gd3PvF5ubJJx0To82SDKMZ+ZPDcFxYLQxA0MJyOTZ7xFbIH73QJi09tJ CRGry4NFla4IfuGJdxF3Lrk859V6OFUHQVASpE2poT8mWpBeAL0WEpWfVbEYyDwX r4fYXx9Y9UmhjJGo/tH3mbyEvr7QSbXBwxW9usz0QoteZCNrnhIfEC4XrALq33Nt ruxqORdEg+rvPU2Br1gy210jxaf+4h1lELsrNiquEb7VAGH/fE84m4USpssNiT2f L5Y/j6igY9t/RjEVwcGhQv5ghxznj+EBb4SPJOI4B92Yig9rzJuvdm6avhF6w+g= =zKuy -----END PGP SIGNATURE-----