-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-mantis-14.0-jessie-amd64-xen.tar.bz2.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-mantis-14.0-jessie-amd64-xen.tar.bz2 66c8c26b3c7aed949d489b06a2afff9f $ sha1sum turnkey-mantis-14.0-jessie-amd64-xen.tar.bz2 8d91fb4441880601f1f7dcb1ce166010bc972690 -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJWMdiBAAoJEIXCXpWhbrlNJ9AIAMLhKStHNl9HiPYntYTKYN5A TfdrbqC/k3MjYIqA6Ob+Khk4LDFGZqR3oitXxhYeXFIZ+I/7RxDmwQptJ07Al5c9 2sUebmLKq+kW171akBnwUJ7dY47CwS1DkUKx67FqZId7Q4iXj4MNkvW9YRZeEBQs b8CP9t5h05NdrOhFbG1hYLWXsr2GZ4XcMQyLyEAmAnh7HH64c8trEY9536U8uJjv 8QrOxiZq33CYl5qC24E/31Md87vK/V0A5b2oSb/XcWoGbdVB6Yyd+OmffY9Ztceq eB4kFEj4hZeDRZmNGzEV6brESITensM7B5Elfd1HqlVcqUfEEO4pt8T1gfv+Pmo= =+2IW -----END PGP SIGNATURE-----