-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify debian-8-turnkey-mantis_14.0-1_amd64.tar.gz.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum debian-8-turnkey-mantis_14.0-1_amd64.tar.gz 05946c37425fa1c82d105728bb62d4f5 $ sha1sum debian-8-turnkey-mantis_14.0-1_amd64.tar.gz b87d0da04afb5f69b186bd99aff40b32d7dad49e -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWObxTAAoJEIXCXpWhbrlNu/oIAOTcSDzfUTj8NFiM8rRMH60R a56BLEWiPK59RzhWwfHLhKRxrx6nS5dkPSEgH71I9Pti/TskEDkUW67prPQypksA G0672Z7STQikl2xz3IHP9rQk9PP7YkK1HBR3tOhov553UOvCeJuQQ9AMZxVccGNF nCKghixh367MWv57z8SHt4TmYjT1X9d+dxKxNYa8xyngpPRv8EAunyOlOp1LE3Vj 0DeKXDLrko2TiHFYZOhjJENMx5ucWOkYZC2dHO8AiadUb5xFUaqGKJzenfCP+hQG gB2vtALrqltAykLzkTeXa09PeT+AuIT9ddkEvIT+dqZSxHb9uR1YKbeM3qT8Ylk= =PXVJ -----END PGP SIGNATURE-----