-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-lapp-14.1-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-lapp-14.1-jessie-amd64.iso 00c856a9bbea6e53a6d757be4f47ebf9 $ sha1sum turnkey-lapp-14.1-jessie-amd64.iso 154fb58c1e31d617ead4520d6e3f14a50d61d312 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkPyAAoJEIXCXpWhbrlNgkUIANHBwET110ypQCfzIJ79Xtp4 dhuy6E0k7cwuNcJdn8wMqy25kPYuHrg3CtKvdldN03MNibL47R5MTkZkB0EI7lBs FGkSHFKfnopzLPFYgY8CzZU4kFBqSBpW9CuS0/PrD9/+meZWHC1n2eGqyZ3vcfGa SJRezwSaOme52MrTmwxoHUtQUe4oRrMG69SmwjNgflcqRA/vK/60rZH6bOiDztw1 HeJYJduVs/R19m3mXEOG5uDN1bIJMAsf6tW1oESTFSbj30gK4iW7R0zppQRCcyA3 79bHCHfCv6hxy4t5pH8EOaT9hL23FrIV5GWdoQF4+MMVRzVDWB/8edtCm+D3Vwo= =UEQU -----END PGP SIGNATURE-----