-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-limesurvey-14.0-jessie-amd64.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-limesurvey-14.0-jessie-amd64.iso c6aca12efddc7fad90147a4df5912264 $ sha1sum turnkey-limesurvey-14.0-jessie-amd64.iso beacf3b8674460ac130604086d0e6fa8e81ab83f -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJV7BrpAAoJEIXCXpWhbrlNiFYIANvxLIM2nyQOyWI3mFXBOkR2 ChNVmZmO2AEbMuvD/RwHObwjw2mcpSvJEPDsCnXR0unC9X3vf7Oa8h8DvxTtg3Ic 86KBctDw5F/J8vIDA8nD3AkizO+aFkQ+iMbhlrTMSJQ/tj1jDSlFmKNitYPm7kQf L/dTaVvpSCDjMl2mOekpYM9X6HFljxu8zzfJ75EPekjwq9pDcpP5q66fr1mZXEC7 5wZmBLU176AWkDpChs63Fz18E7b8fAiYXrvjeN1+b1AawZ4yWcxTMckGxCk/bhT3 Ir9sQQCeczSKOmskeP6hKbG4P8IHvTuAiIvsinJG2qr5LWhxG1rvcG6jQ3kQZxg= =8W51 -----END PGP SIGNATURE-----