-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-gitlab-14.1-jessie-amd64-xen.tar.bz2.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-gitlab-14.1-jessie-amd64-xen.tar.bz2 02b3213ba99ea0583a5848ae7cc5ddfb $ sha1sum turnkey-gitlab-14.1-jessie-amd64-xen.tar.bz2 1ccc8cc89a0ed1c34bc54dcec6f16cbcd3f96a2a -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXRb5nAAoJEIXCXpWhbrlNTc8IALefBY83bJgI69cCZF/2kVO7 Obcvj4J5LMzviSrALCThdSEO0Gw6dW0QOEeN9UXKARh5nxILWC4oWoz72Sc4+u7i mQLqap4abPR3Nj4/xovn0cer7ifESyyzaY4dNr+C4oUTfSRUBSHjSwKUvtCmFJw3 We7WoovsZJOVWAlIdjNLpIB9SRVl4N4/Pr43rxomwmagy2935hTiLiTGRZbLChSB 6GElKiS4vvo6r+SQCsaocbU65FPYp0a02yGCsfoQB75ydqK1ak2ZkBCbtX+oaIKy OhQC/Mnn/idi5skk0JhYMsxvwDS+XxDg8CuVvr7i/OkPlGHotH5Nvv32lWtYl1w= =Mc2l -----END PGP SIGNATURE-----