-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Two steps are required to cryptographically verify image integrity. 1. By verifying the integrity of this signature file, you can be sure that the checksums included in this file are valid. $ gpg --keyserver hkp://pool.sks-keyservers.net --recv-keys 0xA16EB94D $ gpg --list-keys 0xA16EB94D pub 2048R/A16EB94D 2008-08-15 [expires: 2023-08-12] uid Turnkey Linux Release Key $ gpg --verify turnkey-mantis-14.1-jessie-i386.iso.sig gpg: Good signature from "Turnkey Linux Release Key" 2. By calculating the image checksum and validating the hashed value is the same as listed below, you can be sure the image was not corrupted in transit or tampered with. $ md5sum turnkey-mantis-14.1-jessie-i386.iso e69f50eb005a42f991d99e2611b8eb99 $ sha1sum turnkey-mantis-14.1-jessie-i386.iso 4bd2b4f3ad6a57beda4f51f6acbd33356197e26d -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.12 (GNU/Linux) iQEcBAEBAgAGBQJXCkPyAAoJEIXCXpWhbrlNciYIAI3OzXgUSImfpFXAFsTFMP/M leOTRCw+N5RlHjpgfTVEytvVqb3gwmRAO4YV/e9OzmpMkEvz0cYmCN/wN3n+e5qB hMo9I50OpE06+IIh9kRLOJM5GOq6Rvq7p0AU68Jyo8CEpvTa54HKiv/qPVzX1Euv oCbKZBH/yoU0LQ9ygkLDAkGwj3unsFoYdDZa/Lgm30TlZ8x5Jq8j4e9m0fnAYvH1 INOqnARIVmRk4ujzncHXKxvFvp0yRQFcOx1iRuWss/UCCm7UR0KDGL6vJJX3yBA0 uopy3fkcgxyU/OUBNP6B6k/IkJ6IW2whTQYHn7UaL87tBxj7UGww26Fy/48b+tU= =VNFk -----END PGP SIGNATURE-----